Closed
Bug 1427796
Opened 8 years ago
Closed 8 years ago
firefox account secondary email can't use same address as another firefox account
Categories
(Cloud Services :: Server: Firefox Accounts, defect)
Cloud Services
Server: Firefox Accounts
Tracking
(Not tracked)
RESOLVED
WONTFIX
People
(Reporter: bobbuun, Unassigned)
Details
User Agent: Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0
Build ID: 20171206182557
Steps to reproduce:
Create a Firefox account with email address (A).
Create a Firefox account with email address (B).
Log into (B). Try to add same email address as (A) as a "secondary email" for (B).
Actual results:
"Account already exists."
Expected results:
Secondary email address should be any arbitrary email address, irrespective of any other Firefox account existing that utilizes it. Secondary email address SHOULD, of course, be verified after the request, but it shouldn't be restricted from being the same as another account -- especially since the "red route" for many users and uses is to have multiple Firefox accounts.
Comment 1•8 years ago
|
||
Thanks for the report. To be honest I'm not sure how to feel about this from a security perspective, and I expect it would be very complicated for us to change this given the current implementation, but it's an interesting point and I don't want to rule it out out-of-hand. I'm adding a couple of other folks to the bug for their consideration/input.
> especially since the "red route" for many users and uses is to have multiple Firefox accounts.
Sorry, I don't understand what "red route" is, can you say more about your specific use case here?
Just a common, necessary use. One for mobile, one for personal desktop, one for work... Multiple Sync profiles. It's expected behavior, recommended all over in posts/etc about Sync. Since one person's presumed to need multiple accounts, it makes sense that multiple accounts can share the same secondary email address.
Comment 3•8 years ago
|
||
Thanks again for reporting this. After discussion with product and security teams, we've decided not to make any changes to the current implementation; it would simply take us too far away from the current security model design.
Status: UNCONFIRMED → RESOLVED
Closed: 8 years ago
Resolution: --- → WONTFIX
You need to log in
before you can comment on or make changes to this bug.
Description
•