Closed Bug 1762240 Opened 4 years ago Closed 4 years ago

Unauthorized access to sensitive information such as passwords

Categories

(Toolkit :: Password Manager, defect)

defect

Tracking

()

RESOLVED DUPLICATE of bug 1626778

People

(Reporter: pustam1729, Unassigned)

Details

(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])

The bug is with the Mozilla Firefox browser on the Windows platform. When we save passwords for logins, the saved passwords are supposed to be protected from unauthorized persons. It should authenticate the users before letting them view the passwords which are sensitive information. I have reported this vulnerability to the Microsoft Security Team too but they told me to contact you and discuss the issue as this appears to be the only browser to have this issue.

The following steps reproduce the issue.

  1. Install the Mozilla Firefox browser and open it.
  2. Log in to the Firefox account, open any websites & log into them and save the passwords.
  3. Go to passwords and logins in the browser and click on an account.
  4. When you click on the 'eye' icon to view the saved password, the browser does not authenticate you before the access unlike in any other browsers.
  5. You can view all saved passwords without entering the PIN or password.
Flags: sec-bounty?
Component: Security → Password Manager
Product: Firefox → Toolkit

Pustam thank you for filing this bug. User can set up a Primary Password to protect access to their passwords. Also there is a signon.management.page.os-auth.enabled preference in about:config that controls if OS authentication (biometrics) will be used before password is revealed. This pref is turned ON on Nightly builds and is still OFF on Release/Beta.

While these measures are desirable, users should rely on OS authentication to protect themselves and lock their systems before leaving them unattended. The way most OS are designed these days makes it easy enough to steal secrets from unlocked computer.

Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → DUPLICATE
Group: firefox-core-security
Flags: sec-bounty? → sec-bounty-
You need to log in before you can comment on or make changes to this bug.