Unauthorized access to sensitive information such as passwords
Categories
(Toolkit :: Password Manager, defect)
Tracking
()
People
(Reporter: pustam1729, Unassigned)
Details
(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
The bug is with the Mozilla Firefox browser on the Windows platform. When we save passwords for logins, the saved passwords are supposed to be protected from unauthorized persons. It should authenticate the users before letting them view the passwords which are sensitive information. I have reported this vulnerability to the Microsoft Security Team too but they told me to contact you and discuss the issue as this appears to be the only browser to have this issue.
The following steps reproduce the issue.
- Install the Mozilla Firefox browser and open it.
- Log in to the Firefox account, open any websites & log into them and save the passwords.
- Go to passwords and logins in the browser and click on an account.
- When you click on the 'eye' icon to view the saved password, the browser does not authenticate you before the access unlike in any other browsers.
- You can view all saved passwords without entering the PIN or password.
Updated•4 years ago
|
Comment 1•4 years ago
|
||
Pustam thank you for filing this bug. User can set up a Primary Password to protect access to their passwords. Also there is a signon.management.page.os-auth.enabled preference in about:config that controls if OS authentication (biometrics) will be used before password is revealed. This pref is turned ON on Nightly builds and is still OFF on Release/Beta.
While these measures are desirable, users should rely on OS authentication to protect themselves and lock their systems before leaving them unattended. The way most OS are designed these days makes it easy enough to steal secrets from unlocked computer.
Updated•4 years ago
|
Updated•2 years ago
|
Description
•