A better title should be "How I leaked by master key"
A better title should be "How I leaked by master key"
The author's domain seemed familiar, and I noticed a previously popular post which had sort of similar tone, so I think there might be a pattern of writing catchy posts like these. https://fasterthanli.me/articles/i-want-off-mr-golangs-wild-...
That's not what happened at all though. Chrome collected passwords over the years, Safari saved the wrong one, and it leaked all my old passwords - and a few ones I hadn't changed yet.
I spend a large amount of time admitting my mistakes in the article, Google's approach to 2FA is still really surprising to me and a lot of others are hearing about it for the first time.
I get what you’re saying though, no one expects Google’s password management to be so riddled with holes. Encrypting the view or usage of the rest of your passwords with a master password needs to be mandatory, not optional.
I’ve always used Keepass stored on Dropbox and enter my master password everyday, multiple times as it logs out after 3 minutes. I do save some passwords in Firefox but don’t sync those, and 2FA through Microsoft Authenticator (SMS only when it’s the only option). That’s still not perfect but your attack surface doesn’t exist.
This is all really complex for the average person and it took me years as a relatively astute developer to handling properly. A device (something you have) biometric (something you are) authentication should resolve all of these issues in an easy way that you don’t have to think about, and I’m looking forward to ‘sign in with Apple’ to become a universal login for this reason. They nailed this problem, now we need Microsoft and Google to do the same.
It was surprising that you could disable 2FA without using your 2FA. That seems like a big flaw.
The lesson here is to not leave your password manager logged into any machine other than the ones you know are secure themselves. I only do for my phone and personal machine.