Firefox Accounts: Flawed padding validation for RSA signatures
Categories
(Cloud Services :: Server: Firefox Accounts, enhancement)
Tracking
(Not tracked)
People
(Reporter: jwkbugzilla, Unassigned)
Details
(Keywords: reporter-external, sec-low, wsec-crypto, Whiteboard: [reporter-external] [web-bounty-form] [verif?])
Updated•7 years ago
|
Comment 2•7 years ago
|
||
| Reporter | ||
Comment 3•7 years ago
|
||
Comment 4•7 years ago
|
||
| Reporter | ||
Comment 5•7 years ago
|
||
Comment 6•7 years ago
|
||
Comment 7•7 years ago
|
||
| Reporter | ||
Comment 8•7 years ago
|
||
| Reporter | ||
Comment 9•7 years ago
|
||
Comment 10•7 years ago
|
||
Comment 11•7 years ago
|
||
Comment 12•7 years ago
|
||
| Reporter | ||
Comment 13•7 years ago
|
||
| Reporter | ||
Comment 14•7 years ago
|
||
| Reporter | ||
Comment 15•7 years ago
|
||
Comment 16•7 years ago
|
||
Comment 17•5 years ago
|
||
It looks like we no longer use this library in the code to actually verify anything; except in programs in bin/ and test programs. (I presume the programs in bin/ are used - if at all - for testing also.)
If I'm right I think we can close this?
Comment 18•5 years ago
|
||
I believe this code is still used, via browserid-verifier which uses browserid-local-verify which uses browserid-crypto. I was quite hoping that we would no longer be using BrowserID assertions for anything, but here we are in 2020 and they're still kicking around, due entirely to us not prioritizing that work.
Leaving the ni? for myself to come back to this bug with an explanation of how we're not going to be saying that again in 2021...
Comment 19•5 years ago
|
||
We're still working on turning the plan into a concrete bug tree, which is complicated by the fact that it touches several different systems that track their bugs in different places. The plan is to deprecate and remove BrowserID support from all our products, in favour of plain old OAuth2.0 access tokens, and we're getting our heads around it in this document:
https://docs.google.com/document/d/1CnTv0Eamy7Lnbmf1ALH00oTKMPhGu70elRivJYjx5v0/
Comment 20•5 years ago
|
||
We're made some good progress on deprecating BrowserID, and all our sync clients have now moved to OAuth by default. There's still work to do to completely disable the use of BrowserID assertions in our backend systems (ref https://github.com/mozilla/fxa/issues/6940) but it's far enough along that I'm comfortable closing this WONTFIX.
Updated•1 year ago
|
Description
•