User Personal information has no protection
Categories
(Toolkit :: Password Manager, defect, P3)
Tracking
()
People
(Reporter: pernishshukla7, Unassigned)
Details
Attachments
(1 file)
|
3.16 MB,
video/mp4
|
Details |
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.36
Steps to reproduce:
Step to Reproduce
- Open Firefox
- Go to Setting
- Search for Password
- Go to Saved password
- You will find there is no password protection to view password
Actual results:
Because of this attacker can access every account password and email and takeover the account. For example: User forget to shutdown pc. As an attacker i can access everything related to victim through it
Expected results:
Attacker can access user personal detail eg: email & password, Because there is no password protection
| Reporter | ||
Updated•4 years ago
|
Comment 1•4 years ago
|
||
Pernish, thank you for filing this bug. You can setup Primary Password to add extra protection to saved logins.
It's worth to note that if attacker can get access to unlocked OS user account, they can install a keylogger, steal data and cause a lot of trouble. Securing OS account is the most important step to protect personal information.
Updated•4 years ago
|
Comment 2•4 years ago
|
||
The Bugbug bot thinks this bug should belong to the 'Toolkit::Password Manager' component, and is moving the bug to that component. Please revert this change in case you think the bot is wrong.
| Reporter | ||
Comment 3•4 years ago
|
||
Is this report closed?
Comment 4•4 years ago
|
||
(In reply to Pernish Shukla from comment #3)
Is this report closed?
Not yet, I'd like to discuss it with the team on our next meeting first and probably link it to bug 1261977.
The protection exists, but it's an opt-in and users might not be aware that they can set their Primary Password.
| Reporter | ||
Comment 5•4 years ago
|
||
Yeah may be protection exist, but as it contains sensitive information. Password protection should make compulsory to all user. It shouldn't be optional. Because as normal user they only browse and they are unknown about it. None of us will search for primary password. For bug hunters, firefox is top priority browser. Even i didn't know that here isn't password protection. When i navigated to saved password in order to see my saved password, i noticed that there isn't password protection. For example, while using edge,chrome, brave etc browser. They have password protection it's not optional So browser shouldn't make password protection as optional. Hope you got it
Comment 6•4 years ago
|
||
Yep, that's exactly why we aren't closing this bug right away - we need to think of promoting protections.
Updated•4 years ago
|
Updated•2 years ago
|
Description
•