20

This is close to the worst possible design failure, if not the worst. This master key, known as the security domain secret, is temporarily sent to Chrome when a device registers or recovers access to the account. Unit 42 initially found that Chrome exposed the secret in plaintext through its internal FIDO logs. Google removed … Continue reading Google Chrome Password Safe Exposes Master Key in Plaintext →

you are viewing a single comment's thread
view the rest of the comments
[-] be_gt@feddit.nu 4 points 1 week ago

Direct link to actual article

this post was submitted on 08 Aug 2026
20 points (100.0% liked)

Pulse of Truth

2495 readers
75 users here now

Cyber Security news and links to cyber security stories that could make you go hmmm. The content is exactly as it is consumed through RSS feeds and wont be edited (except for the occasional encoding errors).

This community is automagically fed by an instance of Dittybopper.

Commenting rules:

founded 2 years ago
MODERATORS