Feeds

Chrome makes new password grab in version 34

Even with autocomplete off, Google will ask if it can 'help' by storing your passwords

Secure remote control for conventional and virtual desktops

Google has announced that Chrome 34 is now stable enough to be promoted to the Stable Channel. In a few days it will therefore become the default version for millions of users.

Most of the updates to the browser are anodyne: there are 30-odd security fixes, a new look on Windows 8 and what Google labels “Lots of under the hood changes for stability and performance”.

But Chrome 34 will also “ … now offer to remember and fill password fields in the presence of autocomplete=off.” That means that if a website turns off automatic password collection, Chrome will offer to do it anyway if password manager is enabled.

Chromium developers justify this move by saying “It is the security team's view that this is very important for user security by allowing users to have unique and more complex passwords for websites.”

Google also says the decision is in line with its belief in the priority of consistencies, an idea that suggests “In case of conflict, consider users over authors over implementors over specifiers over theoretical purity.”

That last link is to a 2011 post from Chrome security chap Adam Barth and specifically addresses the password manager issue, as follows:

The password manager is a source of conflict for these competing interests. Implementors (myself included) believe that password managers improve security by reducing the costs of using a large number of more complex passwords. Many banks, however, disagree. They believe that password managers reduce security because passwords stored in password managers can be stolen by miscreants.

How do browser vendors resolve this conflict? By default, we enable the password manager. Because users have a higher priority than implementors (i.e., browser vendors), browsers let users turn the password manager off. Because authors (i.e., site operators) also have a higher priority than browser vendors, browsers let authors disable the password manager on their own web sites by setting autocomplete=off.

It's still possible to turn off autocomplete with a “ "--disable-ignore-autocomplete-off"” flag. Just how many average users whose browsers update to Chrome 34 without their intervention care, or care to make that change, is anyone's guess. ®

Beginner's guide to SSL certificates

More from The Register

next story
You really need to do some tech support for Aunty Agnes
Free anti-virus software, expires, stops updating and p0wns the world
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
You stupid BRICK! PCs running Avast AV can't handle Windows fixes
Fix issued, fingers pointed, forums in flames
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Go beyond APM with real-time IT operations analytics
How IT operations teams can harness the wealth of wire data already flowing through their environment for real-time operational intelligence.
The total economic impact of Druva inSync
Examining the ROI enterprises may realize by implementing inSync, as they look to improve backup and recovery of endpoint data in a cost-effective manner.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.