This is close to the worst possible design failure, if not the worst. This master key, known as the security domain secret, is temporarily sent to Chrome when a device registers or recovers access to the account. Unit 42 initially found that Chrome exposed the secret in plaintext through its internal FIDO logs. Google removed … Continue reading Google Chrome Password Safe Exposes Master Key in Plaintext →