topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday April 19, 2024, 2:25 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Last post Author Topic: Chrome’s insane password security strategy  (Read 19680 times)

Vurbal

  • Supporting Member
  • Joined in 2012
  • **
  • Posts: 653
  • Mostly harmless
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Chrome’s insane password security strategy
« Reply #25 on: August 23, 2013, 08:15 AM »
Google's description of how Chrome sync works has the following warning:

Don't sign in to Chrome if you're using a public or untrusted computer. When you set up Chrome with your Google Account, a copy of your data is stored on the computer you're using and can be accessed by other people using the same computer. To remove your data, delete the user you are signed in as.

If you take Google at their word, this indicates that signing out still leaves the synced information stored locally.

Of course, you can use Chrome without ever signing in, but as soon as you do, you have no control over what is spread around through the sync function.  As I said, I use Android devices and I also have ported my home and business phone numbers to Google Voice to keep them when I dumped the landlines they were attached to.  This means I need to sign into my Google accounts regularly. I just don't use Chrome to do so, because I don't want whatever is cached locally from other sessions to be synced to those Google accounts.


You're entitled to your own opinion, but not your own facts. You don't have to assume anything. Significantly more detailed information about how Google Sync works is available on Google's website and the settings themselves make it more than clear. The first time you sign into your Google account using Chrome the settings are chosen by Google, meaning sync everything. If you've already signed in and unselected any of the options, those items will not be synced to the next computer you use.

Google's warning is absolutely true for most people because the settings are hidden and once you've logged in there are no obvious warnings about that. That's dishonest and wrong (some would go so far as to say evil) but still completely different than what you're claiming - by your own admission based almost entirely on assumptions.

No, people shouldn't sign into Chrome because Google refuses to take security or user choice seriously. If you have to rely on FUD to justify it you're not paying enough attention.
I learned to say the pledge of allegiance
Before they beat me bloody down at the station
They haven't got a word out of me since
I got a billion years probation
- The MC5

Follow the path of the unsafe, independent thinker. Expose your ideas to the danger of controversy. Speak your mind and fear less the label of ''crackpot'' than the stigma of conformity.
- Thomas J. Watson, Sr

It's not rocket surgery.
- Me


I recommend reading through my Bio before responding to any of my posts. It could save both of us a lot of time and frustration.

xtabber

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 618
    • View Profile
    • Donate to Member
Re: Chrome’s insane password security strategy
« Reply #26 on: August 23, 2013, 01:24 PM »

You're entitled to your own opinion, but not your own facts. You don't have to assume anything. Significantly more detailed information about how Google Sync works is available on Google's website and the settings themselves make it more than clear. The first time you sign into your Google account using Chrome the settings are chosen by Google, meaning sync everything. If you've already signed in and unselected any of the options, those items will not be synced to the next computer you use.

Google's warning is absolutely true for most people because the settings are hidden and once you've logged in there are no obvious warnings about that. That's dishonest and wrong (some would go so far as to say evil) but still completely different than what you're claiming - by your own admission based almost entirely on assumptions.

No, people shouldn't sign into Chrome because Google refuses to take security or user choice seriously. If you have to rely on FUD to justify it you're not paying enough attention.

Not sure what button I pushed to justify this outburst, but your arguments are neither consistent nor correct.

On the one hand, you complain about Google being dishonest and say that people shouldn't sign in to Chrome. On the other hand, you complain that I don't understand that sync can be turned off and that my arguments about using Chrome are therefore false.

I like much about Google and have used their products for years.  I also have friends who are research scientists there. If Google is,  as you say, dishonest in dealing with users, they are probably less so than most big online players, IMHO, which is why I expect to continue to use their products.  But they make their money almost exclusively by selling targeted advertising, and I am not about to trust them to respect my privacy if they can get away with not doing so.

Sync is not the only reason I don't use Chrome for most browsing, but it IS a security risk unless one is vigilant about making sure that it is always turned off. Unfortunately, Google is relentless about trying to get users to relax their privacy settings. I have personally had the experience of activating a new device on a Google account and suddenly finding settings changed everywhere because some screen had a non-obvious pre-checked option to that effect.

Remember that most security breaches are caused by social exploits, not technical flaws.  Google may not be as reckless in exposing their users to this kind of exploit as, say Facebook, but that is still the foundation of their business model. The best way to avoid getting burned is not to play with fire in the first place.  That's why I rarely use Chrome and advise others not to do so when they have safer alternatives.

Vurbal

  • Supporting Member
  • Joined in 2012
  • **
  • Posts: 653
  • Mostly harmless
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Chrome’s insane password security strategy
« Reply #27 on: August 23, 2013, 02:30 PM »

You're entitled to your own opinion, but not your own facts. You don't have to assume anything. Significantly more detailed information about how Google Sync works is available on Google's website and the settings themselves make it more than clear. The first time you sign into your Google account using Chrome the settings are chosen by Google, meaning sync everything. If you've already signed in and unselected any of the options, those items will not be synced to the next computer you use.

Google's warning is absolutely true for most people because the settings are hidden and once you've logged in there are no obvious warnings about that. That's dishonest and wrong (some would go so far as to say evil) but still completely different than what you're claiming - by your own admission based almost entirely on assumptions.

No, people shouldn't sign into Chrome because Google refuses to take security or user choice seriously. If you have to rely on FUD to justify it you're not paying enough attention.

Not sure what button I pushed to justify this outburst, but your arguments are neither consistent nor correct.

I apologize for using a snarkier tone than I intended.


On the one hand, you complain about Google being dishonest and say that people shouldn't sign in to Chrome. On the other hand, you complain that I don't understand that sync can be turned off and that my arguments about using Chrome are therefore false.

No, I said your facts were inaccurate and supplied a correction. Specifically this fact (emphasis mine)


Of course, you can use Chrome without ever signing in, but as soon as you do, you have no control over what is spread around through the sync function.

It's impossible to reach rational conclusions based on wildly inaccurate facts. I made no assumption about whether this was the basis of your opinion or not. That statement implies, intentionally or not, it's something others should factor into their decision. That muddies the waters and confuses the real issues - the same issues you yourself mention.
I learned to say the pledge of allegiance
Before they beat me bloody down at the station
They haven't got a word out of me since
I got a billion years probation
- The MC5

Follow the path of the unsafe, independent thinker. Expose your ideas to the danger of controversy. Speak your mind and fear less the label of ''crackpot'' than the stigma of conformity.
- Thomas J. Watson, Sr

It's not rocket surgery.
- Me


I recommend reading through my Bio before responding to any of my posts. It could save both of us a lot of time and frustration.

xtabber

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 618
    • View Profile
    • Donate to Member
Re: Chrome’s insane password security strategy
« Reply #28 on: August 23, 2013, 02:43 PM »
Let me then amend that to say that you have no control over what is spread around through the sync function unless you know what your sync settings are and can verify that they are what you think they should be at the moment.

Given that Google has, in my personal experience, changed settings without my being aware of it, and that they furthermore make it difficult for most users to understand those settings and to set them the way they would expect them to be if they did understand, I think my amended statement is true.

AFAIAC, that is a glaring security hole, which I simply don't have the time and energy to step around every time I go online, and don't expect anyone else to, either.

Vurbal

  • Supporting Member
  • Joined in 2012
  • **
  • Posts: 653
  • Mostly harmless
    • View Profile
    • Read more about this member.
    • Donate to Member
Re: Chrome’s insane password security strategy
« Reply #29 on: August 23, 2013, 03:20 PM »
Let me then amend that to say that you have no control over what is spread around through the sync function unless you know what your sync settings are and can verify that they are what you think they should be at the moment.

Given that Google has, in my personal experience, changed settings without my being aware of it, and that they furthermore make it difficult for most users to understand those settings and to set them the way they would expect them to be if they did understand, I think my amended statement is true.

AFAIAC, that is a glaring security hole, which I simply don't have the time and energy to step around every time I go online, and don't expect anyone else to, either.

That I agree with 1000%. Especially in the fact Google counts on their users not recognizing the problem, let alone understanding it. The only safe advice in that case is stay away.

What ordinary people can understand, at least when they can see it, is you don't need to blindly trust or distrust any company. As you correctly pointed out sometimes their business interests are aligned with your privacy and security interests - in Google's case arguably more often than most companies. That's at least a foundation for some degree of trust.

At the end of the day most of us are not Google's customers. We're a commodity. That's neither good nor bad (or at least it's both) as long as we recognize and acknowledge it. It's not foolproof but until we've got crystal balls to see the future imperfect is what we're stuck with.
I learned to say the pledge of allegiance
Before they beat me bloody down at the station
They haven't got a word out of me since
I got a billion years probation
- The MC5

Follow the path of the unsafe, independent thinker. Expose your ideas to the danger of controversy. Speak your mind and fear less the label of ''crackpot'' than the stigma of conformity.
- Thomas J. Watson, Sr

It's not rocket surgery.
- Me


I recommend reading through my Bio before responding to any of my posts. It could save both of us a lot of time and frustration.

mahesh2k

  • Supporting Member
  • Joined in 2007
  • **
  • Posts: 1,426
    • View Profile
    • Donate to Member
Re: Chrome’s insane password security strategy
« Reply #30 on: September 03, 2013, 01:12 PM »
I have this history settings problem with chrome. I wonder if I can disable logging history. Current settings is enabled to "delete history after exit", yet it keeps the history and only destroys the login session.