Bug 1773267 Comment 3 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

> This is still true: if your device gets stolen the primary password protects the stored passwords. That is not the scenario you have described above.
In the second procedure to reproduce I describe how the password protection can be removed: Log out from Sync, reset the Primary Password, log back in to sync, let it sync, and all stored login passwords are freely accessible.

> Tip: Increase protection by enabling a Primary Password on each device. See Use a Primary Password to protect stored logins and passwords.
That doesn't help at all, as the Primary Password can be bypassed within a few minutes with the second procedure to reproduce I described in the ticket description.
Setting a Primary Password is therefore completely useless. It's giving users a feeling of security that is in no way justified.
> This is still true: if your device gets stolen the primary password protects the stored passwords. That is not the scenario you have described above.

In the second procedure to reproduce I describe how the password protection can be removed: Log out from Sync, reset the Primary Password, log back in to sync, let it sync, and all stored login passwords are freely accessible.

> Tip: Increase protection by enabling a Primary Password on each device. See Use a Primary Password to protect stored logins and passwords.

That doesn't help at all, as the Primary Password can be bypassed within a few minutes with the second procedure to reproduce I described in the ticket description.
Setting a Primary Password is therefore completely useless. It's giving users a feeling of security that is in no way justified.

Back to Bug 1773267 Comment 3