Search The Blog
About this site

@RoyOsherove

Subscribe!

This site aims to connect all the dots of my online activities - from tools, books blogs and twitter accounts, to upcoming conferences, engagements and user group talks.

from 5whys.com
Twitter: @RoyOsherove
My Book: The Art of Unit Testing
Latest Posts
« Test Review: MEF | Main | Poll: Which mocking\isolation framework do you use? »
Monday
Oct052009

Why Google Chrome and FireFox are a big security risk for anyone using them

I’ve stopped using Internet Explorer – Too damn slow, memory hogging beast.

I’ve stopped using FireFox, for the same reasons, funnily enough (until I found out about the security flaw).

I’m now using Safari – it’s blazing fast, reliable and does not have that aweful security risk that Chrome does.

What is it?

Google Chrome will reveal your saved passwords to anyone who wants them, with no possibility of securing them with a master password. The image below shows what happens when I use Chrome to save my password for gmail, I can then just go an open chrome options, click “Show Saved passwords” and select a line there, and click “Show password” (in the image that button is titled “Hide password” after clicking it.

image

With Firefox, the default behavior is to allow anyone to see your passwords as well, but you can actively choose to use a master password in firefox to make this less accessible. the default is that it’s open for anyone to see. With Chrome, there isn’t even a “master password” option.

Until they fix this, I am not going to use Chrome, I don’t care how fast it is. Safari is fast and doesn’t show my passwords.

K THX BY

PrintView Printer Friendly Version

Reader Comments (1)

My thoughts on this: don't save passwords on a shared machine! If someone has access to your computer and can access the machine as your user, you're fairly screwed no matter what.

It should be using central system keychain anyway, but hey

June 22, 2011 | Unregistered CommenterMr Dude

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>