Closed Bug 1067163 Opened 11 years ago Closed 11 years ago

Persona sign in security flaw and authenticity error in marketplace

Categories

(Firefox OS Graveyard :: Emulator, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 805608

People

(Reporter: r.gautamkrishna, Unassigned)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:32.0) Gecko/20100101 Firefox/32.0 Build ID: 20140911151253 Steps to reproduce: I had just opened the Firefox OS emulator in my Firefox browser. Opened the marketplace, and clicked the sign-in/sign up button Persona sign in dialog box appeared I entered a fake e mail id: abcd@example.com clicked the continue button then it asked me to set a password, i typed something clicked done button Actual results: It just successfully signed in and i got an input box to enter my name... I can now put reviews in all the apps that are available in the store and write my comments... THIS IS REALLY A BIG SECURITY TREAT Because anyone can just loin using any other person's e-mail ID and can put reviews.. They can even do anything in the marketplace using this ID. Even use it to spam others... I had checked this using my e mail ID. I successfully singed into the marketplace. I got an e-mail from the marketplace saying that my email id is used in marketplace sign in, if its not me just ignore the mail. A normal user only ingnores this mail, so still the hacker will get full access to the user's persona sign-in Developers can use this flaw in putting fake reviews for their app, and can increase the store rating... I have many Firefox OS apps I can simply log out of the account and add a new account and hence i can put many reviews from unique users myself and can improve my apps rating in the marketplace... Expected results: Sign-in with persona must require e-mail verification even for the first sign-up.... After typing the e-mail user must have go to his e mail id and he may be provided with a link to set a password their. he can set a password. then he must come back to the store and enter this to successfully log-in Hence we can solve the authenticity and security problem. as this security flaw can be misused if found by someone else, THIS MUST BE FIXED SOON
Does this work in a real device? It's possible we have a fake Identity provider for example.com for testing purposes in the emulator (but then we shouldn't accept it in the real marketplace, only the testing marketplace).
But it is also a security flaw. because anyone can sign in to anyone's account easily and can put the fake reviews....
Hello.... Need a fix soon. its really important.
Flags: needinfo?(amuntner)
Adamm, can you take a look at this?
Yes, in :30 If I am understanding correctly: an email validation step doesn't happen so that new accounts can be created and logged in to for arbitrary email addresses for which Persona accounts have not previously been created.
Flags: needinfo?(amuntner)
CC'd Andy McKay - I discussed the issue with Andy and he explained that this is a known issue, that there are already open bugs for it, and that for various historical reasons it was a design decision which is changing with the move to Firefox Accounts from persona. Thank you for being observant and taking the time to file a bug report! Documented in 805608, 924985
Status: UNCONFIRMED → RESOLVED
Closed: 11 years ago
Resolution: --- → DUPLICATE
Group: core-security → core-security-release
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: