Browser-laptop: master password for password manager

Created on 15 Apr 2016  路  15Comments  路  Source: brave/browser-laptop

it would be nice to protect visibility of the passwords in the password manager with a master password. similar to firefox.

featurpassword-manager fixed-with-brave-core suggestion wontfix

Most helpful comment

This would be really helpful

All 15 comments

This would be really helpful

I think this would be more than helpful as this is one flaw I see in Brave's mission of keeping your browsing experience more secure. If we click the eye, we should be prompted to enter our user account password similar to how chrome does so (works for windows and mac).

fwiw you can do this right now by locking the system keychain since passwords are encrypted with a master password that is in the keychain. but there could be a more user-friendly way to do it.

Update: I checked as of 0.18, this method still works but you have to restart Brave after locking the keychain. Same as in Chrome.

@NejcZdovc noticed that Chrome prompts for system keychain access when you click to show a password in chrome://settings/passwords. I'm not a huge fan of this approach because it seems like it would give users a false sense of security (since the attacker can just go to the site, have it autofill, then copy the autofilled password into a visible field, given a few more seconds of attack time). However it's another option we could consider.

Also very pro a master password feature, like Firefox has.

In https://www.reddit.com/r/braveproject/comments/7r6awh/brave_password_manager_vs_others/?st=jcjuitcx&sh=13114369, I asked why I should or shouldn't use one manager over another (brave built-in vs. others) - I suppose this is one reason? (lack of master password)

Also, there was a post in the community forums for a "browser password" (super-password) in https://community.brave.com/t/password-protect-browser/4463. This is not the same as this request, but related.

+1 - this holds me back from replacing Firefox

+1
Is there any progress here at all or still just feature request? Seems like a huge offline privacy hole.

+1 here
I think this is a big security issue as commented here:
https://community.brave.com/t/big-security-issue-with-chrome/29221

This is fixed with our Developer channel release 馃槃

When you visit chrome://settings/passwords and try to expose the password by clicking the eyeball, you'll get prompted for your password:
screen shot 2018-09-13 at 10 01 50 am

I'm not sure that the fix described above actually addresses this request. It appears that the approach implemented is to use the keychain, similar to Safari's implementation. This request mostly is about implementing a master password that is independent of the user's local account credentials in the same way that Firefox does. I'm in favour of the master password approach.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

stevespringett picture stevespringett  路  3Comments

mykkymk picture mykkymk  路  3Comments

shortstuffsushi picture shortstuffsushi  路  3Comments

bbondy picture bbondy  路  3Comments

jonathansampson picture jonathansampson  路  3Comments