User Story

• Discuss definition of re-use
• Implement design spec for Reused Passwords Banner Notification
• Learn more link to SUMO page
• update sidebar icon (and tooltip)

Invision spec:


Password reuse is a big problem on the web and causes numerous account compromises.  Users use the same password for the survey site they used one time and their bank account.  If an attacker can compromise one, they can compromise the other.

If a user has saved the same password on multiple sites, perhaps we can somehow flag this in the Password Manager interface.  Particularly if the same password is being used on an HTTP page and an HTTPS page.  Since the former can be read in cleartext, it exposes the later to compromise.
Don't get too naggy about it though. I have 30-ish legitimate instances of my mozilla LDAP password. Even "same eTLD+1" heuristics will get the recommendation wrong because there's a mix of mozilla.ORG and .COM sites, as well as the completely different and
Attached image what-safari-does.png

For reference, what Safari does in Preferences › Passwords.

Mass removing [skyline] and [passwords:management] from about:logins bugs which are no longer useful.

User Story: (updated)
I love the design specs in invisionapp! It looks really cool! I'd love to take on this issue. Would there be anyone open to mentoring this bug (it's totally fine if there isn't--just curious)?

:gliu20 I'd be happy to help with mentoring and there are some other ideas that we need to implement to make that UI much better. The Invision link is a bit old now, there are few elements that will be different.

Hey, sorry for the delay! I've been looking through the source code and trying to understand how the password manager works internally, and what might need to change. I think I'll start out with an initial prototype / mvp first which might take a while.

