Comment 10 for bug 1996267

Revision history for this message
Nathan Teodosio (nteodosio) wrote :

> I don't see how this debate is apropos. Whether or not the passwords are stored in the clear, or obscured with symmetric encryption using hard coded parameters in chrome is irrelevant. Both of these scenarios are entirely unacceptable.

You are right, but if a statement presented as a certainty and is however inaccurate, I think it there is no harm in having a discussion to settle it, because the thread can serve a purpose for other people, and one different from ours.

If it became unclear, the fact that the current behavior is undesired is undisputed.

> So you'll have a tool you can run.. The command will be simple,
>
> xbrowser export chrome passwords
>
> And you'll be able to dump all the passwords.

I've already nudged folks internally and there will be a new review of the auto-connection request, that will be a great proof-of-concept and I thank you in advance.