- Prison Planet.com - http://www.prisonplanet.com -

How Google Chrome Lets Anybody See Your Passwords

Posted By admin On August 17, 2013 @ 4:12 am In Commentary,Featured Stories,Tile | Comments Disabled

Daniel G. J.
August 17, 2013

One of the most popular features of Chrome is its ability to store passwords. That way they pop up automatically when you go to a function like email [1] or Facebook. Elliot Kember [2], a software developer, discovered that anybody who clicks on the Chrome settings icon can see all of the passwords on that computer if he or she goes to the show advanced settings and passwords and forms sections.

The passwords are obscured, but clicking next to them causes them to appear in plain text. The text can be easily copied and emailed or seen by anybody that uses the computer. That means it would be easy for a hacker or malicious stranger that opened a computer with Chrome on it to see all of your passwords.

What’s really disturbing is that the head of Chrome development at Google, Justin Schuh, told [3] The Guardian that he knows all about the flaw. Worse, Schuh said that there are no plans to correct it. In a piece he wrote on the website ‘Hacker News’, Schuh explained:

“…we don’t want to provide users with a false sense of security, and encourage risky behavior. We want to be very clear that when you grant someone access to your OS user account, that they can get at everything.”

One has to wonder why this flaw has not been fixed. It would certainly make a hacker’s job easier, let alone the job of the NSA or spy agency. If the source computer used Chrome, all the hacker would have to do is go to the settings icon to get the user’s email passwords. One security expert told The Guardian:

“The fact you can view the passwords means they are stored in reversible form which means that the dark coders out there will be writing a Trojan to steal that password store as we speak.”

It has been revealed that large Internet companies such as Google and Microsoft have worked closely with the National Security Agency. There is even evidence [4] that Skype (now part of Microsoft) helped the NSA get easy access to customer data. Therefore we need to ask, is this flaw actually helping these companies access your data even easier than before?

The surveillance state might be making it easier than ever for hackers to steal our personal information. The quest for national security appears to be endangering the security of the private individual.

Originally appeared at Story Leak [5].

Article printed from Prison Planet.com: http://www.prisonplanet.com

URL to article: http://www.prisonplanet.com/how-google-chrome-lets-anybody-see-your-passwords.html

URLs in this post:

[1] like email: http://www.storyleak.com/google-admits-that-it-reads-your-email/

[2] Elliot Kember: http://blog.elliottkember.com/chromes-insane-password-security-strategy

[3] told: http://www.theguardian.com/technology/2013/aug/07/google-chrome-password-security-flaw?INTCMP=SRCH

[4] even evidence: http://www.theguardian.com/technology/2013/jun/20/skype-nsa-access-user-data?INTCMP=SRCH

[5] Story Leak: http://www.storyleak.com/google-chrome-anybody-see-your-passwords/

[6] Google spied on British emails and computer passwords: http://www.prisonplanet.com/google-spied-on-british-emails-and-computer-passwords.html

[7] Google’s Wi-Fi snoop nabbed passwords and emails: http://www.prisonplanet.com/googles-wi-fi-snoop-nabbed-passwords-and-emails.html

[8] Google aims to replace passwords with ID ring: http://www.prisonplanet.com/google-aims-to-replace-passwords-with-id-ring.html

[9] Google finally admits that its Street View cars DID take emails and passwords from computers: http://www.prisonplanet.com/google-finally-admits-that-its-street-view-cars-did-take-emails-and-passwords-from-computers.html

[10] Feds tell Web firms to turn over user account passwords: http://www.prisonplanet.com/feds-tell-web-firms-to-turn-over-user-account-passwords.html

Copyright © 2013 PrisonPlanet.com. All rights reserved.