Chrome Now Uses Duplex To Fix Your Stolen Passwords (techcrunch.com) 28
Google announced a new feature for its Chrome browser today that alerts you when one of your passwords has been compromised and then helps you automatically change your password with the help of... wait for it ... Google's Duplex technology. From a report: This new feature will start to roll out slowly to Chrome users on Android in the U.S. soon (with other countries following later), assuming they use Chrome's password-syncing feature. It's worth noting that this won't work for every site just yet. As a Google spokesperson told us, "the feature will initially work on a small number of apps and websites, including Twitter, but will expand to additional sites in the future."
Now you may remember Duplex as the somewhat controversial service that can call businesses for you to make hairdresser appointments or check opening times. Google introduced Duplex at its 2018 I/O developer conference and launched it to a wider audience in 2019. Since then, the team has chipped away at bringing Duplex to more tasks and brought it the web, too. Now it's coming to Chrome to change your compromised passwords for you.
Now you may remember Duplex as the somewhat controversial service that can call businesses for you to make hairdresser appointments or check opening times. Google introduced Duplex at its 2018 I/O developer conference and launched it to a wider audience in 2019. Since then, the team has chipped away at bringing Duplex to more tasks and brought it the web, too. Now it's coming to Chrome to change your compromised passwords for you.
Helping Hand. (Score:3)
So basically Duplex is a digital assistant like what Apple's Knowledge Navigator wanted to be.
Re:Helping Hand. (Score:5, Interesting)
There is actually a standard for this. Sites are supposed to support a standard URL (well-known/change-password) but hardly any do. Shame because it would make life easier.
If Google knows my password have been compromised (Score:2)
Google has to know my passwords, therefore they've been compromised... by Google.
Screw Google with a broomstick. They sure ain't getting my passwords, and I'll take my chances with the other data thieves thank you very much.
Re: If Google knows my password have been compromi (Score:2)
Of course they know.
I can reset my password with them and have access to my synced passwords. This is pretty duh IMO.
Most (not all though) password sync options trade that security for convenience last I checked.
Re: (Score:3, Informative)
> Google has to know my passwords, therefore they've been compromised... by Google.
The better approach is, "if Google can tell if my passwords have been compromised, do they know my passwords?".
That might lead you to discover k-anonymity:
https://blog.cloudflare.com/va... [cloudflare.com]
Re: (Score:2)
How do you think the hash is generated?
Re: (Score:2)
Screw Google with a broomstick ...
Nah, just fuck'em gently. With a chainsaw.
Re: (Score:1)
What ... (Score:1)
Safari does this (Score:2)
My concern is how long is it going to be before banks and the like use this against consumers. Your were told your password was compromised. You d
Re: Safari does this (Score:1)
I would need to have an online relationship with my bank for that to be a problem.
They send me a statement in the mail every month. I have an ATM card, and they still maintain a driveup window even with the pandemic.
Re: (Score:2)
and we are not going to help you get it back
They already said they wouldn't when they renamed "online bank robbery" to "identity theft"
Trusting Google with your passwords is a mistake (Score:4, Insightful)
Re: Trusting Google with your passwords is a mista (Score:1)
I have migrated away from there being anything important on my gmail account. I am using more and more mobile software from F-Droid. I could log entirely outvof Google fairly easily.
For those who haven't explored this: export a copy of your contacts to local storage on your phone. If you disconnect from Google that is one of the most important things they take away.
Re: (Score:2)
Your passwords are stored locally in Chrome and there is an export function. The exported passwords can be imported by Firefox.
Having said that Google could do better. Make humans contactable when things go wrong, and if accounts are locked at least allow the owner to use the Takeout service to get their data.
Re: (Score:2)
There are cases where Google demanded to see scans of passports before lifting Google-wide bans.
You say this like it's a bad thing. I would like to see every company put at least this base level of verification in their service. Way to end SIM swapping fraud and banking fraud in one fell swoop.
Re: (Score:3)
For example, I had Gmail since invite-only which has strong unique password that I periodically change. I never provided Google with a phone number, yet they still regularly lock
False positives (Score:4, Insightful)
Google keeps telling me that one of my passwords has been compromised. When I ask for details it gives me:
Site: http://192.168.1.1/ [192.168.1.1]
User: admin
Password: admin
I'm not sure that counts as a proper compromise. It certainly isn't one of my routers.
Re: (Score:2, Interesting)
Google keeps telling me that one of my passwords has been compromised. When I ask for details it gives me:
Only the one? You haven't seen the worst of Googles problems.
I have 70 such compromised passwords on internal IPs.
Yet when I scroll down the list to the first compromised one, click to show it just to check and make sure, enter my decryption password, then click to delete that entry and get it out of the list... that's when the list jumps to the top.
It can take nearly 2 minutes to check each one.
I'm proverbially 99% sure they are all blank or 'admin' or other defaults.
But since it would take over two hou
Re: False positives (Score:2)
Works just like... (Score:2)
I don't get it (Score:2)
I read TFA and still don't understand why Google needs to call my hairdresser to change my password?
MITM (Score:2)
Then only Google knows your passwords and can lock (Score:2)
you out.
Seriously. A YouTube comment is all it takes to get locked out of your Google account forever.
When only Google knows all of your passwords, you lose your entire online inventory, everything, in an instant, with no appeals process and no chance to get it back, as the recovery mail address is probably also under Google's control and therefore gone.
One comment on YouTube is all it takes to get your online presence cancelled, remember that.
Google is already scanning your personal Google Drive files and