Prompt users to set a primary password upon first password save
Categories
(Toolkit :: Password Manager, enhancement, P3)
Tracking
()
People
(Reporter: furkan-akbulut, Unassigned)
References
(Blocks 1 open bug)
Details
(Keywords: dupeme, Whiteboard: [passwords:master-password] [passwords:primary-password])
Attachments
(1 file)
|
366.46 KB,
application/pdf
|
Details |
| Reporter | ||
Updated•9 years ago
|
| Reporter | ||
Updated•9 years ago
|
Comment 1•9 years ago
|
||
Updated•9 years ago
|
Comment 2•9 years ago
|
||
Updated•9 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
(In reply to Matthew N. [:MattN] (PM me if request are blocking you) from comment #2)
We could put this in a promo box like the sync one that appears below the
capture doorhanger the first N times but that depends on whether UX thinks
it will scare users. Another possible solution is bug 1194529 depending on
who you're trying to stop from accessing the saved passwords locally.
I think making it explicit clear that passwords are stored in the open is just good practice. In this case, scaring a user is a good thing. Don't make creating a master password an option, it is irresponsible these days.
Comment 6•5 years ago
|
||
(In reply to John King from comment #5)
I think making it explicit clear that passwords are stored in the open is just good practice.
Passwords are never stored in plaintext but without a master password having the salt (stored in key*.db) is enough to decrypt them.
In this case, scaring a user is a good thing. Don't make creating a master password an option, it is irresponsible these days.
If you use whole disk encryption and lock your operating system account when you're away from the computer then that is sufficient to stop local attacks.
Updated•4 years ago
|
Updated•4 years ago
|
Updated•4 years ago
|
Comment 7•3 years ago
|
||
I think this would be a good idea.
Consider, for example, things like the recent scams where people are tricked into screen sharing with control by a caller. In that case it is very easy to upload the files somewhere and get access to all passwords.
Or just having access to someone else's computer. There is a difference between being able to go to the settings and read passwords and just being able to log into some site on the spot.
Updated•3 years ago
|
Updated•1 month ago
|
Updated•1 month ago
|
Description
•