Ramblings of an old Doc

 

I’m not referring to skinning. Don’t get me wrong, it’s a good browser, and a fast one.

The flaw is a serious one, though. While logon data (password and username) were stored in plaintext without any sort of protection, the use of a master password could have prevented possible breaches…but that could open the user’s computer to other attacks as well.

Now, another flaw has come to light. Identity Finder has found this:

“Last week, Identity Finder security researchers performed in-depth scans on several employee computers using the latest version of Sensitive Data Manager (SDM). During the scan, SDM pinpointed several Chrome SQLite and protocol buffers storing a range of information including names, email addresses, mailing addresses, phone numbers, bank account numbers, social security numbers and credit card numbers.  SDM found similar data among all employees who consistently use Chrome as their primary browser…. Chrome browser data is unprotected, and can be read by anyone with physical access to the hard drive, access to the file system, or simple malware. There are dozens of well-known exploits to access payload data and locally stored files.” – Identity Finder

So, how to protect yourself if you use Chrome (besides another browser, which that firm hasn’t yet tested)?

“Anytime you enter a credit card number or other [personal information] into a form, be sure to “Clear saved Autofill form data”, “Empty the cache”, and “Clear browsing history” from the past hour and the information you typed will be erased. Alternatively, disabling Autofill or using Incognito mode will protect form data.” – ibid

The mechanics:

“After opening Chrome, click “Customize and control Google Chrome”, then Settings, then scroll down to “Show advanced settings” then click “Clear browsing data…”. Once the Clear browsing data dialog popup appears, enable the checkmark for “Clear saved Autofill form data”, “Empty the cache”, and “Clear browsing history”. Configure the time setting to include when you typed sensitive data such as “the past hour” [or “since the beginning of time”] then click the button on bottom right: “Clear browsing data”. Then, restart Google Chrome.” – ibid

You’ll have to do that after each session.

Sources:

http://www.ghacks.net/2013/10/12/google-chrome-saves-sensitive-data-entered-https-websites-plaintext/?_m=3n%2e0038%2e1033%2ehj0ao01hy5%2e12ca

http://www.identityfinder.com/blog/


Comments (Page 1)
2 Pages1 2 
on Oct 14, 2013

which is too much for every session, there must be an extension to do this for you? ... considering that Opera uses Chrome code now, it might pay for anyone with Opera to look into if their browser is doing the same thing.

on Oct 14, 2013

Indeed...

The best I've seen is "Click & Clean", but you'll still have to open it (right side of your browser bar and click on the 'Options', and do it at the end of each browser session, as far as I can see.

on Oct 14, 2013

I don't rely on the browser to Auto-Fill forms. Never have.

I use Roboform for that and have done so for at least 10 years.

 

on Oct 14, 2013

I clean up Chrome daily. Pain in the butt logging in on certain sites but I can live with that. As for auto-fill, its disabled as I never use it. 

on Oct 14, 2013

Phoon

I don't rely on the browser to Auto-Fill forms. Never have.

I use Roboform for that and have done so for at least 10 years.

 


Isnt roboform just a addon ? if so the data will be still saved in the chrome cache...
I thank you DOC for pointing this out 
Just to say that the solution of click and clean is ok but should not be needed on a browser that is used by the majority.
On my Home computer i run TU its set to clean browser history cache and cookies daily when going idle.
But this topic reminds me that i have to find a new browser one that isnt a target for exploits

on Oct 14, 2013

Roloccolor
But this topic reminds me that i have to find a new browser one that isnt a target for exploits

Good luck, if you find one and other people find it no doubt it will become popular and then you can guess what will happen.  

on Oct 14, 2013

true but first it needs to get popular... but i doubt i will find something good reliable and fast 

on Oct 14, 2013

be sure to “Clear saved Autofill form data”, “

I don't THINK roboform is populating that data. I have autofill turned off. Roboform just fills in the forms being shown. Now, if I had autofill turned on it may want to save that in a separate file/database somewhere, but I doubt it is since it is off. In any case, I tend to clear all the browsing data on a daily basis. Repeatedly.

 

As a matter of fact, I just checked this theory. I did not empty my history or data. I went to chrome://settings and looked at the Passwords and forms section. On this particular machine I had both options checked, but.... when I look at the Manage Autofill settings, and Manage saved passwords sections they are empty. That is because I've never told the browser to save this info, even when it asks. So, Roboform use would not present any risk at all in this scenario.

on Oct 14, 2013

Lots of paranoid internet users here on WC.

on Oct 14, 2013

Just who do you mean, kona?

on Oct 14, 2013

People looking over their shoulders it seems. Deleting browsing data every day, nor using auto fill, clearing this or that. Whatever. I've used Firefox for years. In all that time I have never had any issues. And I don't clear my setting or browsing data everyday, and I do use auto fill.

I guess I'm different. I just don't have issues.

on Oct 14, 2013

Some people care about losing banking data, passwords, social security numbers, etc. Go figure.

on Oct 14, 2013

kona0197
People looking over their shoulders it seems. Deleting browsing data every day, nor using auto fill, clearing this or that. Whatever. I've used Firefox for years. In all that time I have never had any issues. And I don't clear my setting or browsing data everyday, and I do use auto fill.

I guess I'm different. I just don't have issues.

on Oct 14, 2013

DrJBHL
Some people care about losing banking data, passwords, social security numbers, etc. Go figure.

I care about those things as well. Just never had any issues. I was pointing out that I don't take such extreme measures. Some people take it to the extreme when that's not really needed. Tin foil hat anyone?

on Oct 14, 2013

It's sort of like pregnancy, kona: Either a browser is secure or it isn't. I don't care if your data is secure if you don't. There are people who do care. These articles are for them. You're always free not to read them and not to comment.

2 Pages1 2