Chromium and saved passwords

In my recent review of “chromium”, I mentioned that it offers to save passwords, and stores them in kwallet.  This suggests that they should be stored in encrypted form, due to the way that kwallet works.

Unfortunately, things may be worse.  I recently tested out “chromium” while logged into Gnome.  And when I visited a site where chromium had a saved password, it filled in the password field.  But I was never prompted for the key to unlock kwallet.

It now looks as if “chromium” is saving the passwords in kwallet, where they are encrypted.  But it is apparently also saving them in an unencrypted (but obscured) file in the user chromium profile directory.

This is not good.

How I use firefox

In my series of browser reviews, I indicated that I would later post about how I use firefox.  So it’s time for that report.  While I’m not doing anything especially unusual, this might indicate why I continue to prefer firefox.


I like to keep the number of extensions small.  But some extensions are important, and are a major reason for preferring firefox.  The main extensions that I use are “NoScript”, “Secure Login”, “Saved Password Editor” and “FlashBlock”.

Stupid bank security

I’ll be commenting on those answers to special questions that some banks use.

Yesterday, I logged into my bank site to check the balance.  The first page I saw told me how they were going to protect my security.  Then I was asked for information.  The first item was a phone number.  Okay thus far, though I’m pretty sure that they already know that.

The next information was three questions to which I should supply answers.  I had some choice in the questions.

Using ecryptfs with opensuse 12.2

[Update: it appears that the ecryptfs kernel module may need to be loaded before you can setup a private directory.  See the comments below, particularly my reply with time stamp of “2012/09/10 at 22:16”.]

It has been a while since I first posted on ecryptfs, and there have been some changes (improvements) with opensuse 12.2.  My earlier post was about my experimenting.  Some time in the near future, I will do a more complete post about ecryptfs.  For now, this will be specific to using it with opensuse 12.2, and about what has changed since that earlier post.

My linux accounts

I plan a post on installing linux.  This is a preliminary posts on the user accounts that I setup as part of the installation.

Three accounts

I use three accounts.  The login names for those three accounts are:

  1. support
  2. rickert
  3. nwr

Security “experts” – a rant

Some internet sites have ordinary security.  They require an account and password for access, but they don’t go to special lengths.  And then there are those who use a security expert (or a security BOFH).  I’ll call those the “super-security” sites.

