> According to the chromium documented cited, this is wrong.

Maybe it's a different way of interpreting the terminology.

If it applied a rot13 to your password (of course that would be very
stupid but it's just for the sake of the argument) and stored that in a
file, I could say that it is stored in plain text and that however they
aren't stored in the clear, i.e. they are not stored exactly as they
are, there is some sort of transformation*, trivial or not, applied to
them.

Otherwise, you could prove me wrong by pointing to the file where you
see Chromium password stored in the clear.

> For many people an autoconnect for the password-manager-service would
probably solve this

Then you're welcome to follow up in [1], in which the automatic
connection of the interface has been declined. I cannot override the
policy reviewers' decision.

*I think the transformation is the one Evan Carroll describes in
LP:2038875.

[1] https://forum.snapcraft.io/t/auto-connecting-the-cups-control-and-
password-manager-service-interfaces-for-the-chromium-snap/4592/6

-- 
You received this bug notification because you are a member of Desktop
Packages, which is subscribed to chromium-browser in Ubuntu.
https://bugs.launchpad.net/bugs/1996267

Title:
  [snap] Doesn't store encrypted passwords unless interface is connected

Status in chromium-browser package in Ubuntu:
  Confirmed

Bug description:
  In the Snap package of Chromium, Chromium is not protecting passwords
  with gnome-keyring (or KWallet).

  As a result, copying the Chromium profile directory from the snap
  directory gives access to all stored passwords. This is a HIGH
  security risk. Regular users who are used to storing their passwords
  in browsers are probably unaware of this.

  Note that Chromium is started with the command line option
  “--password-store=basic”. This hack should never have been released to
  the public.

  The Chromium documentation states:
  > --password-store=basic (to use the plain text store)

  
https://chromium.googlesource.com/chromium/src/+/master/docs/linux/password_storage.md

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/chromium-browser/+bug/1996267/+subscriptions


-- 
Mailing list: https://launchpad.net/~desktop-packages
Post to     : desktop-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~desktop-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to