> I don't see how this debate is apropos. Whether or not the passwords
are stored in the clear, or obscured with symmetric encryption using
hard coded parameters in chrome is irrelevant. Both of these scenarios
are entirely unacceptable.

You are right, but if a statement presented as a certainty and is
however inaccurate, I think it there is no harm in having a discussion
to settle it, because the thread can serve a purpose for other people,
and one different from ours.

If it became unclear, the fact that the current behavior is undesired is
undisputed.

> So you'll have a tool you can run.. The command will be simple,
>
>    xbrowser export chrome passwords
>
> And you'll be able to dump all the passwords.

I've already nudged folks internally and there will be a new review of
the auto-connection request, that will be a great proof-of-concept and I
thank you in advance.

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to chromium-browser in Ubuntu.
https://bugs.launchpad.net/bugs/1996267

Title:
  [snap] Doesn't store encrypted passwords unless interface is connected

Status in chromium-browser package in Ubuntu:
  Confirmed

Bug description:
  In the Snap package of Chromium, Chromium is not protecting passwords
  with gnome-keyring (or KWallet).

  As a result, copying the Chromium profile directory from the snap
  directory gives access to all stored passwords. This is a HIGH
  security risk. Regular users who are used to storing their passwords
  in browsers are probably unaware of this.

  Note that Chromium is started with the command line option
  “--password-store=basic”. This hack should never have been released to
  the public.

  The Chromium documentation states:
  > --password-store=basic (to use the plain text store)

  
https://chromium.googlesource.com/chromium/src/+/master/docs/linux/password_storage.md

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1996267/+subscriptions


-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : [email protected]
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to