2.11.1 (L1) Ensure 'Enable leak detection for entered credentials' Is Set to 'Enabled'

Information

This policy controls the ability for Google Chrome to verify if any entered credentials were part of a leak. If a user's credentials are compromised, the user will be alerted. The password is not stored on Google's servers unless Password Sync is enabled, and is encrypted with a secret key known only to your device. To find out more on how Google protects your password, see their support article How Chrome protects your passwords https://support.google.com/chrome/answer/10311524?sjid=2728402513461545685-NA#zippy=%2Chow-password-protection-works%2Chow-we-protect-your-data%2Cyoure-in-control.

Users should be aware if any of their credentials have been compromised or leaked.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled :

Computer Configuration\Policies\Administrative Templates\Google\Google Chrome\Password Manager\Enable leak detection for entered credentials

Impact:

There should be no impact on the user.

See Also

https://workbench.cisecurity.org/benchmarks/23110

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-8, CSCv7|4.8

Plugin: Windows

Control ID: b57b39a2fa8d7d9a8e041ab21d9f561409f0a3d44a6f741f70634afae6df94de