Closed Bug 1742989 Opened 3 years ago Closed 5 months ago

Review our advice on secure passwords [off-train]

Categories

(support.mozilla.org :: Knowledge Base Content, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: serg, Assigned: dgalindo)

References

Details

To create a quality password, your primary password should include the following:

At least one capital letter.
One or more digits.
At least one non-alphanumeric character, such as: @ # $ % ^ & * ( ).

from https://support.mozilla.org/en-US/kb/use-primary-password-protect-stored-logins?as=u&utm_source=inproduct&redirectslug=use-master-password-protect-stored-logins&redirectlocale=en-US#w_create-a-primary-password

Does it make passwords more secure? Password1! and Password@13 fits the description. I doubt these extras make them less guessable.

What are the criteria for a strong password?
Firefox Accounts makes sure that your password meets the following criteria:
It has at least eight characters.
The password does not contain any part of your email address.
Does not match the description of most common passwords.

from https://support.mozilla.org/en-US/kb/password-strength

This is better, but 8 characters long password is not enough. In 2012 it was possible to "brute force every possible eight-character password in just 5.5 hours".

We can use our new password on several different websites by adding a prefix or suffix with a mnemonic link to a particular site.
#Hihas4ei:AmZ for Amazon
fCb#Hihas4ei: for Facebook
#Hihas4ei:YtB for YouTube
dRm#Hihas4ei: for Drumbeat

from https://support.mozilla.org/en-US/kb/create-secure-passwords-keep-your-identity-safe

This is suggesting to reuse password. A breach on one site will made user vulnerable on others.

Additional links to revisit:

https://monitor.firefox.com/security-tips#strong-passwords
https://support.mozilla.org/en-US/kb/how-generate-secure-password-firefox

Lets improve our suggestions on generating strong memorable password.
Lets suggest using a password manager, built-in or external.
Lets try to unify all "password strength" articles in one page. We should give consistent direction to users.

Summary: Review our advise on secure passwords → Review our advice on secure passwords
Component: Password Manager → Knowledge Base Content
Product: Toolkit → support.mozilla.org
Assignee: nobody → aparise
See Also: → 1559986
Type: enhancement → task
See Also: → 1865866
See Also: → 1877475
Assignee: aparise → lsiebert

Updates to the articles on securing stored logins with a primary password (https://support.mozilla.org/en-US/kb/use-primary-password-protect-stored-logins) and creating secure passwords to keep your identity safe (https://support.mozilla.org/en-US/kb/create-secure-passwords-keep-your-identity-safe) are now available. Updates for additional articles are planned for completion next week.

A bit of feedback on these:

It is good that there is a single page for password creation advice (https://support.mozilla.org/en-US/kb/create-secure-passwords-keep-your-identity-safe). However, the advice on that page is not very good, for the reasons Sergey lists. I also see that the primary password page still includes advice on password construction that could simply be removed.

In terms of what should be said, XKCD advice is pretty solid, but we should really not be telling people to perform this task themselves in most cases. Firefox has a password generator. We should encourage people to use that, or the password generator that is in their password manager of choice.

The primary password is a case where the string might need to be remembered more than other passwords. However, if we are considering loosening advice on automatic generation, that needs to be carefully considered.

Summary: Review our advice on secure passwords → Review our advice on secure passwords [off-train]

Update: The article is archived and marked as obsolete.

Status: NEW → RESOLVED
Closed: 9 months ago
Resolution: --- → FIXED
Status: RESOLVED → REOPENED
Flags: needinfo?(lsiebert)
Resolution: FIXED → ---

From bug 1865871 comment 10

After some conversations with Mandy, Konstantina and Jo through Slack it was decided to redirect the Create secure passwords to keep your identity safe KB to the Choose a strong password KB.

Since the Create secure passwords to keep your identity safe article now redirects to the Mozilla account-related Choose a strong password article:
I submitted a revision that's pending review, to update the Choose a strong password article so that it also applies to creating secure passwords in general, not just for Mozilla accounts. See https://support.mozilla.org/en-US/kb/password-strength/history

Dayana, can this bug be reassigned, since Lucas is not longer on SUMO staff?

Flags: needinfo?(dgaleano)
Flags: needinfo?(lsiebert)

(In reply to Alice Wyman from comment #8)

Since the Create secure passwords to keep your identity safe article now redirects to the Mozilla account-related Choose a strong password article:
I submitted a revision that's pending review, to update the Choose a strong password article so that it also applies to creating secure passwords in general, not just for Mozilla accounts. See https://support.mozilla.org/en-US/kb/password-strength/history

Dayana, can this bug be reassigned, since Lucas is not longer on SUMO staff?

Hi Alice, thanks for flagging. I've re-assigned to Dayani. She can review your pending revision.

Assignee: lsiebert → dgalindo
Flags: needinfo?(dgaleano) → needinfo?(dgalindo)

Hey Mandy, should this be added to Asana?

Flags: needinfo?(mcacciapaglia)
Flags: needinfo?(mcacciapaglia) → needinfo?(oopdahl)

(In reply to Alice Wyman from comment #8)

Since the Create secure passwords to keep your identity safe article now redirects to the Mozilla account-related Choose a strong password article:
I submitted a revision that's pending review, to update the Choose a strong password article so that it also applies to creating secure passwords in general, not just for Mozilla accounts. See https://support.mozilla.org/en-US/kb/password-strength/history

Dayana, can this bug be reassigned, since Lucas is not longer on SUMO staff?

Reviewed! Thanks Alice.

Status: REOPENED → RESOLVED
Closed: 9 months ago5 months ago
Resolution: --- → FIXED
Flags: needinfo?(dgalindo)
Flags: needinfo?(oopdahl)
You need to log in before you can comment on or make changes to this bug.