Google, Microsoft can get your passwords via web browser's spellcheck

Discussion in 'other security issues & news' started by Rasheed187, Sep 19, 2022.

  1. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    You have to be freaking kidding me right? Don't these companies feel any shame? :eek:

    https://www.bleepingcomputer.com/ne...t-your-passwords-via-web-browsers-spellcheck/
    https://www.otto-js.com/news/articl...check-features-expose-pii-even-your-passwords
     
  2. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    You couldn't make this stuff up. :eek:

    I'm pretty sure shame is not in their collective dictionary vocabularies (see what I did there?).
     
  3. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, I see what you did there. :p

    And I'm actually surprised that nobody else responded, as if this was already to be expected from these companies LOL. I'm lucky that I never used the ''enhanced spell check'' in Vivaldi, I wouldn't be surprised if it also suffered from this ''bug''.
     
  4. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    Time to start buying old fashioned hard copy dictionaries I think. Or maybe live in a Faraday cage ...
     
  5. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    I just sent a company wide email yesterday warning everyone here of this. Unbelievable. This can't be an accident.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    It's absolutely crazy. By now everyone should know that Chrome and Edge are basically spyware. It's best to switch to Vivaldi, Brave or Firefox. Although I also don't fully trust Brave and Firefox to be honest. And it's not clear if this bug is also present in other Chromium based browsers like Vivaldi, Opera and Brave.
     
  7. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Are we assuming this is a bug? These are 2 of the biggest, if not the 2 biggest tech companies in the world. An error of judgement maybe. Maybe.
     
  8. noway

    noway Registered Member

    Joined:
    Apr 24, 2005
    Posts:
    461
    Glad I use Firefox!
     
  9. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Yes, I'm trying to be friendly. But I also don't believe this was a bug, because they should have known that such a feature could leak sensitive data, but they simply don't care. But I have been saying for years that Chrome is spyware, this isn't exactly the first scandal. Edge is probably not much better.
     
  10. Azure Phoenix

    Azure Phoenix Registered Member

    Joined:
    Nov 22, 2014
    Posts:
    1,560
    Is that feature even enabled by default in Chrome?

    From what I read, it isn’t. Then the number of users potentially affected by this bug shouldn’t be huge.

    With that said, this doesn’t mean it shouldn’t be fixed or improved.
     
  11. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    I agree. From what I've read you have to enable it in Chrome. For Edge you must go to greater lengths: install extension.

    I still have a copy CD with dictionary of my native language and some python script that can change it format to old-fashioned open source dictionary program just in case :)
     
  12. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    Not much greater lengths. I have found it on every PC in the office so I think the extension finds you instead of the other way around.
     
  13. reasonablePrivacy

    reasonablePrivacy Registered Member

    Joined:
    Oct 7, 2017
    Posts:
    2,010
    Location:
    Member state of European Union
    Ok, my bad. I didn't know that.
    BTW The company I work in blocklisted all extensions unless they are on allowlist long ago. Blocklist is implemented by * (wildcard) in some registry key. I believe accidentally company is secure from that password-leaking.
     
  14. xxJackxx

    xxJackxx Registered Member

    Joined:
    Oct 23, 2008
    Posts:
    8,645
    Location:
    USA
    That's a good idea. I should consider doing the same.
     
  15. imdb

    imdb Registered Member

    Joined:
    Nov 2, 2011
    Posts:
    4,208
    one of the very first things i do when setting up a new browser is to disable the autocomplete and spellcheck features. :ninja:
     
  16. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    That could work lol.
     
  17. Rasheed187

    Rasheed187 Registered Member

    Joined:
    Jul 10, 2004
    Posts:
    17,559
    Location:
    The Netherlands
    Good point, but it's still not acceptable, like you already said. And who knows how many of these extra features can leak sensitive data. The best option is to drop Chrome and Edge as soon as possible, if you ask me.

    Oh, didn't know about this, you need an extension in Edge for this? Must have missed this.

    LOL, why isn't this a surprise to me?
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.