Vai Google darbinieki var redzēt manas saglabātās Google Chrome paroles?

Satura rādītājs:

Vai Google darbinieki var redzēt manas saglabātās Google Chrome paroles?
Vai Google darbinieki var redzēt manas saglabātās Google Chrome paroles?

Video: Vai Google darbinieki var redzēt manas saglabātās Google Chrome paroles?

Video: Vai Google darbinieki var redzēt manas saglabātās Google Chrome paroles?
Video: Ram Slots 1 3 Vs 2 4| Which Slot Order to Fill First? Clear-cut Explanation - YouTube 2024, Aprīlis
Anonim
Jūsu paroles saglabāšana jūsu tīmekļa pārlūkprogrammā, šķiet, ir lieliska laika taupīšana, bet vai paroles ir drošas un nepieejamas citiem (pat pārlūkprogrammas uzņēmuma darbiniekiem), kad viņi svēra?
Jūsu paroles saglabāšana jūsu tīmekļa pārlūkprogrammā, šķiet, ir lieliska laika taupīšana, bet vai paroles ir drošas un nepieejamas citiem (pat pārlūkprogrammas uzņēmuma darbiniekiem), kad viņi svēra?

Šodienas jautājumu un atbilžu sesija mums priecājas par SuperUser - Stack Exchange dalību, kas ir kopienas vadīta Q & A tīmekļa vietņu grupa.

Jautājums

SuperUser lasītājs MMA ir ziņkārīgs, ja Google darbiniekiem ir (vai var) piekļūt parolēm, kuras viņš saglabā pārlūkprogrammā Google Chrome:

I understand that we are really tempted to save our passwords in Google Chrome. The likely benefit is two fold,

  • You don’t need to (memorize and) input those long and cryptic passwords.
  • These are available wherever you are once you log in to your Google account.

The last point sparked my doubt. Since the password is available anywhere, the storage must in some central location, and this should be at Google.

Now, my simple question is, can a Google employee see my passwords?

Searching over the Internet revealed several articles/messages.

  • Do you save passwords in Chrome? Maybe you should reconsider: Talks about your passwords being stolen by someone who has access to your computer account. Nothing mentioned about the central storage security and vulnerability. There is even a response from Chrome browser security tech lead about the first issue.
  • Chrome’s insane password security strategy: Mostly along the same line. You can steal password from somebody if you have access to the computer account.
  • How to Steal Passwords Saved in Google Chrome in 5 Simple Steps: Teaches you how to actually perform the act mentioned in the previous two when you have access to somebody else’s account.

There are many more (including this one at this site), mostly along the same line, points, counter-points, huge debates. I refrain from mentioning them here, simply carry a search if you want to find them.

Coming back to my original query, can a Google employee see my password? Since I can view the password using a simple button, definitely they can be unhashed (decrypted) even if encrypted. This is very different from the passwords saved in Unix-like OS’s where the saved password can never be seen in plain text.

They use a one-way encryption algorithm to encrypt your passwords. This encrypted password is then stored in the passwd or shadow file. When you attempt to login, the password you type in is encrypted again and compared with the entry in the file that stores your passwords. If they match, it must be the same password, and you are allowed access. Thus, a superuser can change my password, can block my account, but he can never see my password.

Tātad viņa bažas ir pamatotas vai mazliet ieskatu kliedētu viņa uztraukumu?

Atbilde

SuperUser ziedotājs Zeel palīdz atrisināt viņa prātu:

Short answer: No*

Passwords stored on your local machine can be decrypted by Chrome, as long as your OS user account is logged in. And then you can view those in plain text. At first this seems horrible, but how did you think auto-fill worked? When that password field gets filled in, Chrome must insert the real password into the HTML form element – or else the page wouldn’t work right, and you could not submit the form. And if the connection to the website is not over HTTPS, the plain text is then sent over the internet. In other words, if chrome can’t get the plain text passwords, then they are totally useless. A one way hash is no good, because we need to use them.

Now the passwords are in fact encrypted, the only way to get them back to plain text is to have the decryption key. That key is your Google password, or a secondary key you can set up. When you sign into Chrome and sync the Google servers will transmit the encrypted passwords, settings, bookmarks, auto-fill, etc, to your local machine. Here Chrome will decrypt the information and be able to use it.

On Google’s end all that info is stored in its encrpyted state, and they do not have the key to decrypt it. Your account password is checked against a hash to log in to Google, and even if you let chrome remember it, that encrypted version is hidden in the same bundle as the other passwords, impossible to access. So an employee could probably grab a dump of the encrypted data, but it wouldn’t do them any good, since they would have no way to use it.*

So no, Google employees can not** access your passwords, since they are encrypted on their servers.

* However, do not forget that any system that can be accessed by an authorized user can be accessed by an unauthorized user. Some systems are easier to break than other, but none are fail-proof… That being said, I think I will trust Google and the millions they spend on security systems, over any other password storage solution. And heck, I’m a wimpy nerd, it would be easier to beat the passwords out of me than break Google’s encryption.

** I am also assuming that there isn’t a person who just happens to work for Google gaining access to your local machine. In that case you are screwed, but employment at Google isn’t actually a factor any more. Moral: Hit Win + L before leaving machine.

Lai gan mēs piekrītam Zeel, ka tā ir diezgan droša beta (ja vien jūsu dators nav apdraudēts), ka jūsu paroles ir drošībā, kamēr tās tiek glabātas pārlūkā Chrome, mēs vēlamies šifrēt visus mūsu pieteikumus un paroles LastPass vaultā.

Vai kaut ko pievienot paskaidrojumam? Skatieties komentāros. Vēlaties lasīt citas atbildes no citiem tehnoloģiju savvy Stack Exchange lietotājiem? Šeit skatiet pilnu diskusiju pavedienu.

Ieteicams: