Beware the Google Password Manager
fasterthanli.me
fasterthanli.me
A better title should be "How I leaked by master key"
It was surprising that you could disable 2FA without using your 2FA. That seems like a big flaw.
The lesson here is to not leave your password manager logged into any machine other than the ones you know are secure themselves. I only do for my phone and personal machine.
The author's domain seemed familiar, and I noticed a previously popular post which had sort of similar tone, so I think there might be a pattern of writing catchy posts like these. https://fasterthanli.me/articles/i-want-off-mr-golangs-wild-...
That's not what happened at all though. Chrome collected passwords over the years, Safari saved the wrong one, and it leaked all my old passwords - and a few ones I hadn't changed yet.
I spend a large amount of time admitting my mistakes in the article, Google's approach to 2FA is still really surprising to me and a lot of others are hearing about it for the first time.
I get what you’re saying though, no one expects Google’s password management to be so riddled with holes. Encrypting the view or usage of the rest of your passwords with a master password needs to be mandatory, not optional.
I’ve always used Keepass stored on Dropbox and enter my master password everyday, multiple times as it logs out after 3 minutes. I do save some passwords in Firefox but don’t sync those, and 2FA through Microsoft Authenticator (SMS only when it’s the only option). That’s still not perfect but your attack surface doesn’t exist.
This is all really complex for the average person and it took me years as a relatively astute developer to handling properly. A device (something you have) biometric (something you are) authentication should resolve all of these issues in an easy way that you don’t have to think about, and I’m looking forward to ‘sign in with Apple’ to become a universal login for this reason. They nailed this problem, now we need Microsoft and Google to do the same.
There is no way to delete all of your passwords saved by Google other than one. at. a. time.
There are lots of instructions on how to do it ( https://support.google.com/accounts/thread/3509905?hl=en , https://support.google.com/chrome/answer/95606?hl=en , https://support.google.com/chrome/thread/5688847?hl=en , https://superuser.com/questions/1106689/how-do-i-delete-all-... )
None work (as of late 2019, the last time I tried).
Very few daemons are secure enough to expose to the open internet. OpenSSH is one of the few.
(And, if possible, even network access to ssh should be blocked by the cloud provider's firewall. Access should only be permitted from the user's public IP)
As I was wading through paragraph after paragraph where the author acknowledged fault and berated himself for it, I was thinking, "This is annoying, but I know if he doesn't write all this crap, someone out there will just ignore everything else he writes. They probably will anyways..."
And sure enough, here you are!
Moral of this story for people who write things online: Don't worry about the critics. You can't please them no matter what you write, or how much you bow and scrape and beg forgiveness for your human frailty up front, there will always be someone who will be a jerk.
I consider my Google account to be very high priority in terms of keeping the login secure. Accordingly, I would never log into it on a remote machine like that. I keep APP on, and I'm not sure if I even could, what with the security key requirements. But such a remote machine is IMO always just too vulnerable to various types of compromise. One of the reasons I still have a Google account, for all of their faults, is that I think they're the best in the industry for blocking account takeover attempts.
Article OP didn't say why he felt the need to log into his Google account on a remote server meant for CI builds and with relatively low security. I think that would be the first point to address. There's just too many ways to compromise things once you make that mistake, and I wouldn't want to count on all of the other security bits being just right for an attacker not to be able to escalate that kind of access somehow.
In this case something with NoMachine exposed/disabled the device password as well.
Essentially the OP's configuration allowed an attacker unfettered access to the machine while a "blessed" chrome session was still active and had their master password stored in Safari.
One thing the article lacks - it talks about (and even recommends) being able to pick a different passphrase, but offers no guidance for how someone might go about doing that.
I looked, but couldn't see anything. Not in Chrome, not in passwords.google.com, not in Android.
I have long since switched to using 1Password for everything, but it was seeing passwords.google.com for the first time that freaked me out enough to switch to a passphrase.
> I enquired how did they know a lock screen was actually set up, let alone solved recently, and the answer was: "on Android, we know - for Windows & macOS, we'd probably need browser extensions".
This blew my mind. How many Google security experts worked on their model and how did they all think "...and obviously we can assume every user has a secure login set up on every machine"?!
It looks like that's the default, but that's another good way you can avoid this issue - if you do have to log in to Google on a machine with lower security, be sure to uncheck that box.
(It's already bad enough that Gmail is probably the account recovery email, even if the passwords stored in the password manager.)
It got me to go through my accounts and delete the 5 or so password that managed to get into that manager over the years.
Usually Chrome prompts me to enter my windows pin before showing me my password. The attacker also needs to know my Windows pin/pass to see those passwords.
This has nothing to do with Google Password Manager.
You leak your password storage master password, you're going to have a bad day..
Everything's back to normal, thanks for caring.