Chrome - Why am I automatically authenticated to a web app even after clearing browser cookies?

Posted by Howiecamp on Super User See other posts from Super User or by Howiecamp
Published on 2013-10-24T15:06:14Z Indexed on 2013/10/24 15:58 UTC
Read the original article Hit count: 247

I am accessing a web application using Chrome. If I sign out of the app and clear all Chrome history/cookies/etc (even Flash cookies which are now handled by Chrome in the same Clear History area) and then re-access the site, I am automatically logged in without being prompted for credentials.

I then launched Chrome in Incognito mode and was able to reproduce the same behavior. However, the I was prompted upon the first logon while in Incognito mode.

The web application behaves as expected in Internet Explorer 10.

Some info about the application:

  • It's a Sharepoint site using NTLM authentication
  • The credentials are Active Directory-based, as the username is domain\username
  • My connection is over the Internet and there is no AD relationship between my local Windows account, my Windows PC. In other words I (meaning my locally logged on user and my PC) are not in any way part of their AD domain.
  • The site is running SSL on port 443

Why might Chrome be automatically authenticating me?

© Super User or respective owner

Related posts about google-chrome

Related posts about security