Type in a very few words into Google Chrome browser – the market share leader in most surveys – anda full list of websites and their associated passwords displays onthe screen.

|

Reported by UK software developer Elliot Kember, the phrase that unlocks the password display is:chrome://settings/passwords. Type that into the browser address barand it reveals a list of saved passwords. Highlight a site andwhat's shown is the password in plain text.

|

Wrote Kember in his blog, “They [everyday users] don't expect itto be this easy to see their passwords. Every day, millions ofnormal, everyday users are saving their passwords in Chrome. Thisis not OK.”

|

In a test by a reporter, Chrome indeed displayed a lengthy lineup of some two dozen saved passwords for sites ranging fromHootsuite to Twitter. Also included was the master login to anumber of Google accounts including GMail,

|

Not included in the list were any financially related sites. Nocredit union, no bank, no PayPal, no credit card issuers.

|

UK newspaper The Guardian reported that the head of Google's Chrome team indicated thereare no plans to change this system.

|

Many users are said to save their passwords by sending emails tothemselves, so that their email box becomes a de facto passwordcache. Access the email and those passwords, theoretically, couldbe found.

|

To exploit Kember's vulnerability, a criminal would need to findan unattended computer, with Chrome installed. What would then berevealed are the passwords which the user elected to save inChrome.

Complete your profile to continue reading and get FREE access to CUTimes.com, part of your ALM digital membership.

  • Critical CUTimes.com information including comprehensive product and service provider listings via the Marketplace Directory, CU Careers, resources from industry leaders, webcasts, and breaking news, analysis and more with our informative Newsletters.
  • Exclusive discounts on ALM and CU Times events.
  • Access to other award-winning ALM websites including Law.com and GlobeSt.com.
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.