Open Bug 1565326 Opened 6 years ago Updated 1 year ago

[meta] Login breach/vulnerable alerts/indicators in about:logins

Categories

(Firefox :: about:logins, enhancement)

70 Branch
enhancement

Tracking

()

Tracking Status
relnote-firefox --- 70+
firefox70 --- fixed

People

(Reporter: groovecoder, Unassigned)

References

(Depends on 10 open bugs, )

Details

(Keywords: meta)

Attachments

(2 files)

No description provided.
Depends on: 1563802, 1564539, 1565267
Whiteboard: [skyline]

Note: to test this in the about:logins UI, the saved login must be older than the breach date of the site. To develop and test this manually I had to:

  1. Create a new Firefox profile for dev/testing
  2. In the profile, save a login for a breached site - e.g., https://eatstreet.com/
  3. Close Firefox
  4. In the profile's file directory, open the logins.json file - e.g., ~/Library/Application\ Support/Firefox/Profiles/cqr0e53v.mach/logins.json
  5. Find the item for eatstreet.com
  6. Update its "timePasswordChanged" value to before the breach date - e.g., 1556773200000 is May 2, which is 1 day before the breach of eatstreet.com
  7. Save the logins.json file and close it
  8. Open Firefox again using the same profile
  9. Firefox should show a breach indicator on the saved login for eatstreet.com
Depends on: 1569846
Depends on: 1569847
Depends on: 1569848
No longer depends on: 1569847
Depends on: 1569855
Depends on: 1572118
Depends on: 1573461
Summary: [meta] Monitor breach indicators → [meta] Monitor breach indicators in about:logins
Depends on: 1573843
Depends on: 1575220
Depends on: 1576047
Depends on: 1576177
Depends on: 1576175
Depends on: 1577808

Release Note Request (optional, but appreciated)
[Why is this notable]:
This brings Firefox Monitor functionality into the Firefox/Lockwise password manager

[Suggested wording]:
The Lockwise password manager interface includes breach alerts from Firefox Monitor.

SUMO link (not written yet): https://support.mozilla.org/kb/alerts-breached-websites-firefox-lockwise

relnote-firefox: --- → ?

Removing priority from meta bug as we'll track the work bugs.

Priority: P1 → --
Whiteboard: [skyline]
Depends on: 1584103
Depends on: 1583985
Depends on: 1585629

(In reply to Luke Crouch [:groovecoder] from comment #2)

Release Note Request (optional, but appreciated)
[Why is this notable]:
This brings Firefox Monitor functionality into the Firefox/Lockwise password manager

[Suggested wording]:
The Lockwise password manager interface includes breach alerts from Firefox Monitor.

SUMO link (not written yet): https://support.mozilla.org/kb/alerts-breached-websites-firefox-lockwise

Updated SUMO link: https://support.mozilla.org/kb/firefox-lockwise-alerts-breached-websites

Depends on: 1590522
Assignee: lcrouch → nobody
Component: Password Manager → about:logins
Product: Toolkit → Firefox
Target Milestone: mozilla70 → ---
Depends on: 1118553
Depends on: 1592464
Depends on: 1592467
Depends on: 1118558
Depends on: 1592469
Summary: [meta] Monitor breach indicators in about:logins → [meta] Login breach/vulnerable alerts/indicators in about:logins
Depends on: 1592670
Depends on: 1592673
Depends on: 1592675
Depends on: 1592677
Depends on: 1592678
Depends on: 1592679
Depends on: 1592682
Depends on: 1592779
Depends on: 1595922
Depends on: 1626119
Depends on: 1627404
No longer depends on: 1627696
Depends on: 1593095
Depends on: 1644338
Severity: normal → S3

To test the functionality in the about:logins UI, where the saved login must predate the site's breach date, follow these steps:

Create a new Firefox profile for development/testing purposes.
Within this profile, save a login for a site known to have been breached, for example, "customstickers.com/".
Close Firefox.
Navigate to the profile's file directory and open the "logins.json" file (for example, at "~/Library/Application Support/Firefox/Profiles/cqr0e53v.mach/logins.json").
Locate the entry for "eatstreet.com".
Change the "timePasswordChanged" value to a date before the site's breach date. For instance, setting it to "1556773200000" corresponds to May 2, which is one day before the breach at "eatstreet.com".
Save and close the "logins.json" file.
Reopen Firefox using the same profile.
Upon doing this, Firefox should display a breach indicator for the saved login on "customstickers".

You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: