Google account password recovery.

No you don't and that is the whole 'trick' to recovering a password on a active device you have forgotten. I've never visited that site in my life before and I doubt many people are even aware of it's existence.

I use passwords.google.com as my Password Manager which may be why my experience differs.

Will test it later today.

I cannot "see" any of my passwords in the browser, that functionality has been removed completely as it now lives in the cloud and behind the passwords.google.com authentication layer.

And trust me, loads of people are aware of it as it's another Google service.
 
Doesn't work. The hint is that page asks about passwords for OTHER sites, not the guys google account.

If I try on my phone, browser, my dogs back, going to passwords.google.com always asks for my google password first.

If you tap on the passwd field it brings up a list of accounts and I can select any of my gmail accounts and it will populate the passwd field with that accounts passwd.
 
If you tap on the passwd field it brings up a list of accounts and I can select any of my gmail accounts and it will populate the passwd field with that accounts passwd.

Not for me, not until I have passed "verify that its you" which required my google password. After that yes, I can click on passwords all over the show and they are shown
 
Doesn't work. The hint is that page asks about passwords for OTHER sites, not the guys google account.

If I try on my phone, browser, my dogs back, going to passwords.google.com always asks for my google password first.

Not for me, not until I have passed "verify that its you" which required my google password. After that yes, I can click on passwords all over the show and they are shown

Thank you! I'm clearly not losing my mind and these okes are just operating some shockingly insecure setups.

Just chrome sync doing it's business. You can tell it to not sync any passwords.

I'm fully aware and do it with intention.

However mine is nowhere near as insecure as described here.
 
I did steps 2-3 on my phone and it shows me my passwd.

Step 3 is gonna ask you for a passwd and when you tap on the passwd field it will bring up a list of accounts and select the gmail one and then tap the eye once the passwd field is populated with dots.

You might as well get the passwds for all the listed ccounts if he has more than one.

Back to this point.

There is no "eye symbol" outside of Passwords.Google.com and you require authentication to get there.

So you must be running something third party or otherwise differently configured to get that results following a similar process.

Your process however isn't exactly the same as listed...because like I said there is no eye symbol so you couldn't have done steps 2 and 3 with a different website.

What does this page of yours look like?

https://i.imgur.com/5iO9B8D.png

Cause you are either running a very old version of Chrome or have something not configured because it shouldn't work like that and is horribly insecure.
 
Last edited:
Okay digging deeper it seems for Android you need to have enabled Smart Lock at some point for it to encrypt it like this.

Your passwords are saved to your Google Account if either of the following are true:

You're signed in to Chrome and are syncing passwords, or
You're using Smart Lock for Passwords on Android
Otherwise, your passwords are only stored on Chrome on your computer.

As for PC if you are signed in and syncing it should be encrypting it as expected.

If you aren't signing in and syncing like that then I would highly recommend you start doing it immediately otherwise anyone whoever touches your machine has full access to all your authentication data.

https://support.google.com/chrome/answer/95606?co=GENIE.Platform=Desktop&hl=en

You can access locally saved passwords by going to Settings > Advanced > Manage Passwords but this still requires (at least on Windows) your login password to view anything so it's still behind an authentication layer.

If definitely shouldn't just show it "in browser" by clicking the little eye button without asking twice.
 
Last edited:
There is no "eye symbol" outside of Passwords.Google.com and you require authentication to get there.

So you must be running something third party or otherwise differently configured to get that results following a similar process.

It's NOT on PC but it is there on Android.

To see passwords you’ve saved to Chrome through your Android device or PC, follow these instructions.

If you’re accessing the passwords through your Android device follow these steps:

1. Sign into Chrome by opening Chrome on your phone, clicking the menu (icon) on the top right corner, and signing in to your account.
2. Next, type in passwords.google.com into your address bar
3. Under the Saved passwords section your saved passwords will be listed. Click on any of those and your password will appear as a row of dots, if you click the eye symbol next to the dots, it will reveal the exact text of your password.

Is there a way to video record on android so I can demonstrate this?
 
You can access locally saved passwords by going to Settings > Advanced > Manage Passwords but this still requires (at least on Windows) your login password to view anything so it's still behind an authentication layer.

If definitely shouldn't just show it "in browser" by clicking the little eye button without asking twice.

Or chrome://settings/passwords
 
It's NOT on PC but it is there on Android.

Your the one who stated it did this on your PC.


Is there a way to video record on android so I can demonstrate this?

I know nothing about Android and wasn't commenting on that at all.

Or chrome://settings/passwords


Yup same thing. BUt again there is an authentication layer before it just shows anything.

If Android differs in that regard...great in this instance...but terrible for security.
 
Where did I mention anything about an eye next to the password field on pc? I looked and cannot find it.

You copied the text that mentioned it and said you did the same Step 2 & 3.

Evidently you didn't do the same thing.
 
You copied the text that mentioned it and said you did the same Step 2 & 3.

Evidently you didn't do the same thing.

On my phone, i did it on my android phone,

I did steps 2-3 on my phone and it shows me my passwd.

Step 3 is gonna ask you for a passwd and when you tap on the passwd field it will bring up a list of accounts and select the gmail one and then tap the eye once the passwd field is populated with dots.

You might as well get the passwds for all the listed ccounts if he has more than one.
 
Last edited:
Thank you! I'm clearly not losing my mind and these okes are just operating some shockingly insecure setups.
It's not insecure and it's been like this for decades on all platforms and all browsers. This is technically a hack so you can't blame the platform.
 
It's not insecure and it's been like this for decades on all platforms and all browsers. This is technically a hack so you can't blame the platform.

Just becuase it's been like this for an age across many browsers and deemed acceptable doesn't mean it's not insecure.

It's horrendously insecure. Anyone with a bit of knowledge has all the access in the world to your stuff.

More so to be exploited by anyone who isn't too savvy and gives their password to a stranger thinking they can just change it later.

And it's not a hack at all, it's wide open. Especially in Firefox if you don't set a master password.

At least Chrome by default blocks open access to it now.
 
Just becuase it's been like this for an age across many browsers and deemed acceptable doesn't mean it's not insecure.

It's horrendously insecure. Anyone with a bit of knowledge has all the access in the world to your stuff.

More so to be exploited by anyone who isn't too savvy and gives their password to a stranger thinking they can just change it later.

And it's not a hack at all, it's wide open. Especially in Firefox if you don't set a master password.

At least Chrome by default blocks open access to it now.
Technically it is a hack as you're doing something to circumvent a security measure. And therein lies the rub, if you don't set a master password or a password for your pc it's always been insecure by default. You need access to the pc first in which case even a master password wouldn't help against a keylogger.
 
Where did I mention anything about an eye next to the password field on pc? I looked and cannot find it.

I was only trying it on my phone, again I needed to verify first and only afterwards I could see the passwords
 
Top
Sign up to the MyBroadband newsletter
X