Use Logins protected by a Primary Password (old Master Password)
Categories
(Toolkit :: Password Manager, defect)
Tracking
()
People
(Reporter: johnmaverick74, Unassigned)
Details
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:84.0) Gecko/20100101 Firefox/84.0
Steps to reproduce:
I have a few passwords saved in Lockwise.
I've set a master password to avoid others that access my browser from revealing and reading them.
I then try to access a page to which i have a saved login
Actual results:
The page asks me for the master password.
Expected results:
I expected the users could use the saved logins to access the webpages normally (since i allowed them to use my browser/profile).
I was hopping they would just be blocked from being able to reveal and read my passwords.
I can also imagine this being useful on a business where one allows users to access webservices (SaaS) without having to reveal them the logins that are being used.
Comment 1•5 years ago
|
||
Bugbug thinks this bug should belong to this component, but please revert this change in case of error.
Comment 2•5 years ago
•
|
||
Thanks for filing Maverick, hoping I can provide some clarity on why the primary password prompt is appearing in your case. From the related support article, "Important: After you have defined and set your primary password, you will be prompted to enter it once for each Firefox session, when Firefox needs access to your stored passwords. This also applies if you want to add, remove or show a password." Since you have a login on x site and you have primary password enabled, the browser will prompt you for your primary password (if you aren't authorized) because the password manager is attempting to autofill your credentials on x site. This is expected behavior.
Unfortunately, there are no plans to implement a behavior like you describe, "I was hoping they would just be blocked from being able to reveal and read my passwords". If someone is able to get your credentials autofilled into a site, then they could copy them and paste them into notepad and be able to see them in plaintext. This same behavior is expected with any password manager, which is why we're prompting for your primary password before autofilling credentials.
Thanks again for filing and I hope this helps!
(In reply to Tim Giles [:tgiles] from comment #2)
If someone is able to get your credentials autofilled into a site, then they could copy them and paste them into notepad and be able to see them in plaintext. This same behavior is expected with any password manager, which is why we're prompting for your primary password before autofilling credentials.
Thanks again for filing and I hope this helps!
Hi Tim, thank you so much for your reply!
About your explanation: i don't know about macOS, but i was not able to replicate the issue neither in Windows, neither in Linux.
Both OS's did not allow me to copy-paste a saved password to notepad in order to reveal it.
I don't know how other browsers work (even with a few recent firefox frustrations i've been using it exclusively since around v1 ), but an option to allow the use of the credentials without seeing them would be really useful on a personal level and on a business level (i can tell you about a practical example where this would be very useful on a business, if you're interested).
Is there anything else i can do that make take this into reconsideration?
thank you
Description
•