Closed Bug 1716145 Opened 5 years ago Closed 5 years ago

Passwords are visible in Password manager, across all Mozilla based (products Opera also )

Categories

(Toolkit :: Password Manager, defect)

Firefox 89
defect

Tracking

()

RESOLVED WONTFIX

People

(Reporter: richard.jewell, Unassigned)

Details

User Agent: Mozilla/5.0 (Linux; Android 11; SM-G998W Build/RP1A.200720.012; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/91.0.4472.101 Mobile Safari/537.36 EdgW/1.0

Steps to reproduce:

Open Firefox > Passwords

View all saved passwords and get a list of accounts. Select an account and click on the eye to see the password.

This reveals the password on the account and can be done to every saved account to get a list. So somone with access to this page can get login details and associated passwords.

This is OK if you set your Firefox sync account so that you have to log in to it every time. Although still not good.

The bigger risk is if the operating system saves your sync and save a count account password. In this case only access to the pc, phone etc is all that is needed to fast track to the liston someone's passwords.
This would be possible on a work machine, a computer tech would have access for example.

This option is extremely dangerous. And an extreme security vulnerability.

Actual results:

A person can see account names and the.associated passwords accross all.of the saved password accounts in Firefox. In fact all.mozilla products

This appears to be applicable accross all mozila platforms and products.
I now have to go and change all my passwords AND any system I use to remember or create the password. I also need to try and delete.any Firefox.sync accounts and data I had. Hmmm

Expected results:

The password should be encrypted and should never be available to view in this account space.
The option and the password data field for each account should be not accessible to view, copy , or other ways of gleaning the password stored in the field

This should be applied across all mobile products and platforms

The typical use (of a phone, especially) is for single-user systems. If you share access to the same OS account with someone you don't trust they could install any number of spy programs to recover this data. However, if you are concerned we do have an option to encrypt your passwords and not only trust the OS file access controls:
https://support.mozilla.org/en-US/kb/use-primary-password-protect-stored-logins

Data that lives in our Sync service is always encrypted on your machine before it's sent to Sync. Mozilla never has access.

We have long argued over whether passwords should default encrypted or not so I'm closing this bug and urge you to lobby in developer forums or our customer feedback mechanisms instead.

Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 5 years ago
Component: Untriaged → Password Manager
Product: Firefox → Toolkit
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.