Chrome to be deployed by US State Department
geek.com
geek.com
Securing the best vehicle for navigating the network has proven quite a bit harder. Keep in mind, State is quite small compared to some other agencies, and most people with secrets are pretty sharp, and they are working infinitely more with information than with physical security.
Also, if we have stuff that obviously needs to be heavily secured, we use other networks.
For the NIPRnet, firefox_vs_opera_vs_ie.jpg remains fairly relevant: http://imgur.com/SYgZ5
Security is always bulletproof until it isn't.
Every company probably has people clamoring for modern browsers. Don't sites like Facebook and Gmail no longer function under older versions of IE? Those versions are particularly prevalent at megacorps.
If the State Department is comfortable with their employees using Chrome, why not [insert random business/organization still clinging to IE out of tradition/"security"].
"No doubt, the State Department will officially adopt Facebook at about the same time the revenue-challenged site follows Friendster into social networking oblivion"
I read a lot of stuff, every day, about how evil google and its chromey thing steal all our personal information and use it to advance their super villain take over of the world.
So, um, why would any body bothered by security want to use google?
Its like "Q" department being supplied by Dr No.
http://www.securitynewsdaily.com/496-hacking-contest-smashes...
"Google’s Chrome Web browser managed to remain untouched. In fact, Computer World reported that nobody even attempted to crack into Google Chrome , despite the $20,000 Google offered to anyone who could successfully exploit it."
Not sure what you are trying to get at with your post? Are you implying that NaCL is vulnerable because of it's nature and now will be an major attack vector?
But NaCL in my view can be made(or already is in my opinion) solid and with more focus will become safer and coupled with fast updates, it should make it a lot less of an issue as Flash or ActiveX vulnerabilities have been.
It still has a pretty serious security hole: Passwords are visible in plain text. A quick trip into "Personal Stuff" and "Manage saved passwords..." is all you need in order to expose this info.
I ran a quick test. Without straining much, you can click the "show" button on about 40 passwords in one minute. A quick Ctrl+P and the entire list is printed in plain text! It probably wouldn't take much longer than that to email it or transmit the plain text list via some other method.
If you have three to five minutes on someone's workstation you can walk away with the login information for absolutely everything they've done through the browser, banking, social, email, whatever.
What sucks is that people have been very vocal on the Chrome support forum about this particular issue and, well, they've been summarily ignored.
Maybe I'm missing something fundamental here but I just can't understand why Google would leave this huge gaping hole in there. It can't be that hard to at least provide one more layer of security. You should not be able to see any passwords without a master password.
I've looked at some of the arguments pointing out that this could provide a false sense of security. My point (and that made by countless others) is very simple: The way it works today a ten-year-old could steal all of your passwords inside of five minutes without even having to work very hard. A layer or two of security would make it so that a far more knowledgeable and seriously involved process (or spying software) would have to be utilized to steal your stuff. I vote for option #2.
I use Chrome as my primary browser, but I am not a civil servant at a government office. I am keenly aware of the security hole.
That said, I don't recommend it to family and friends because a non-techie will screw themselves in an instant with this browser. Imagine Uncle Pete taking his laptop to be serviced and having all of his personal login data fully exposed to the 17-year-old pimple-faced kid at the computer shop. Terrible stuff.
Google: Please fix this before it becomes the source of embarrassment and huge personal loss to lots of people.
HN can be really weird sometimes.
Yes, it would probably be nice if Chrome had the kind of protection of passwords database with a master password that Firefox does. But it still isn't a "security hole".
It might be a good UI change, but agreed that it isn't the kind of "security" that the State Department is concerned about.
Walking away from an unlocked machine isn't the only scenario that would expose personal login data this way.
Also, my post refers to a more general use of Chrome. I would hope that a government installation might have several layers of security on top of any application in order to prevent these holes from being exploited.
The "Uncle Pete" example is a very real and plausible scenario.
The fact that nearly anything on a computer is hackable isn't the point either. I kind of draw the line at the stage where a precocious ten year old can steal your data while jumping on one foot and whistling the latest Lady Gaga song with one hand tied behind his back and one eye closed.
If that doesn't define a security hole I don't know what would.
It's not a slam dunk that Chrome would be better if it had a master password anyway given that rarely used passwords tend to be forgotten quickly, and no one wants Chrome to inflict us with some Vista UAC clone.
Finally, it's extremely annoying to read hyperbolic comments in which the author responds to criticism by redirecting to some irrelevant corner case viz "my post refers to a more general use of Chrome". If that were really the case, then why "the sky is falling" tone in the original post?
How many pieces of software on a typical computer hold information that, if it got into the wrong hands, could literally ruin somene's life? For the average Internet user the browser is the only answer. I can't understand why it is that it is wrong to demand at least enough access difficulty to frustrate a smart ten year old.
Here's the other problem: Google, as far as I know, does not make the user aware of the potential exposure. This can't be good.
It might not be 100% hacker safe, but it is 100% employee safe at my workplace, which makes a world of difference.
Given that scenario, someone up to no good who stays behind with the express purpose of stealing personal data can have a treasure trove of information by the time everyone is back. And --again, this is my biggest point-- they don't have to be a hacker to do this. All they have to do is point and click and they got everyone's data (and the businesses data as well).
It's about time that Google fix this so that it actually requires some skill and effort to steal your data.
This is also one of the reasons none of my notebooks have Chrome. Imagine loosing it or having it stolen.
Of course unless you want to play the oldest trick in the book the "lost despatches trick" (see operation mincemeat for a ww2 example) it might be an advatage :-)
Up until browsers it is unlikely that a single piece of software on millions of computers held the keys to someone's entire personal and financial life. Sure, some --few-- people might have kept that data in unencrypted text files, but it is probably fair that this was ver, very rare.
Today millions store access data to everything they do on the net, from financial to social, in their browsers.
Is it too much to ask that browser makers take the stuff seriously and give the user the option to protect this data?
Give the techies the option to turn it off if they wish. For uncle Pete it should be turned on by default.
Simply put, if you let someone have unrestricted access to your account, then it's not your account anymore. There's nothing the browser can do to change that. If you need further clarification, I encourage you to read through the bugs filed for this request:
http://code.google.com/p/chromium/issues/detail?id=53 http://code.google.com/p/chromium/issues/detail?id=1397 http://code.google.com/p/chromium/issues/detail?id=92117