Closed Bug 1627625 Opened 5 years ago Closed 5 years ago

bug in password security

Categories

(Thunderbird :: Security, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1612717

People

(Reporter: cv.schmitt, Unassigned)

Details

(Keywords: regression)

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:74.0) Gecko/20100101 Firefox/74.0

Steps to reproduce:

Here is Solus Linux 4.1 with the most actual packages
(last update was recently 5th April)
I have changed password at google in its gmail account.
But then in thunderbird no new login-prompt ?!

Actual results:

It seems that, new password was tried by attacker to be phished ?!

Expected results:

A new login window should appear for to type new password (for gmail account).
And I dont want to save the password - then at each time I call up thunderbird, there
should be a login with password prompt.
(Have I to disable gmail in smartphone?)

Or it might be a little conflict between Gnome (gdm) and thunderbird
because of Login - management ?!

Component: Untriaged → Security

Please describe the actual results in Thunderbird after changing your password in GMail via a web browser.

Flags: needinfo?(cv.schmitt)

You can go into the password manager and manually delete the old pwd as a workaround.
This will be fixed iin 68.7 which will be out in a few days.

Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Keywords: regression
Resolution: --- → DUPLICATE

(In reply to Magnus Melin [:mkmelin] from comment #3)

You can go into the password manager and manually delete the old pwd as a workaround.
This will be fixed iin 68.7 which will be out in a few days.

*** This bug has been marked as a duplicate of bug 1612717 ***

It seems to be fixed with thunderbird update (downgrade?) with version 68.6.0 in Solus Linux 4.1 - but
when password settings is set to "encrypted" password, then authentification cannot be done because of
an intermezzo with imap at google.com - so thunderbird program is then urging me to set the password as normal.
This way there is then no intermezzo with authentification error of encrypted password any more.

So now password is set to "normal" and each time at login and each time for to use thunderbird, then
thunderbird is making a query for password. Why does this not work, when password is set to encrypted ?

Flags: needinfo?(cv.schmitt)

Upgrade to 68.7, not .6.

You need to log in before you can comment on or make changes to this bug.