Closed Bug 1773267 Opened 4 years ago Closed 4 years ago

Security vulnerability: Primary Password can be bypassed with Firefox Sync

Categories

(Toolkit :: Password Manager, defect)

Firefox 101
defect

Tracking

()

RESOLVED INVALID

People

(Reporter: bugzilla, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:101.0) Gecko/20100101 Firefox/101.0

Steps to reproduce:

Procedures to reproduce the issue:

  • Set up the Primary Password in Firefox.
  • Save a website's login username and password in Firefox.
  • Verify you can access the password only after entering the Primary Password.
  • Set up Firefox Sync.
  • Set up second device to be included in the Sync.
  • Trigger the syncing process by clicking on "Sync now" in Firefox on both devices.
  • Access all saved passwords on the second device without having to enter the Primary Password.

The bypassing is also possible without a second device by following these steps:

  • Set up the Primary Password in Firefox.
  • Save a website's login username and password in Firefox.
  • Verify you can access the password only after entering the Primary Password.
  • Set up Firefox Sync.
  • Click on "Sync now" to trigger the syncing.
  • Click on "Logout..." to log out from Firefox Sync.
  • Use the method described in the Help pages to reset the Primary Password (chrome://pippki/content/resetpassword.xhtml, click on "Reset": now the Primary Password is removed and all saved logins have disappeared.
  • Log in to Firefox Sync again.
  • Click on "Synchronize now" to trigger the sync process.
  • Shut down Firefox and start it again.
  • Access all saved passwords without any prompt for the Primary Password.

Actual results:

With the described methods I am able to simply bypass the Primary Password, which makes the setting of it completely useless.

Expected results:

When I set up a Primary Password, I do this under the assumption that if my device gets stolen, the thief has no way to access the passwords that are secured with it, at least not easily. Firefox itself puts out this message when setting up a Primary Password: "If you forget your Primary Password, you will be unable to access any of the information protected by it on this device." This is simply not true.

If passwords are protected with a Primary Password, the passwords should ONLY be accessible after entering the Primary Password, and under no circumstances, the passwords should be stored anywhere without being encrypted without the Primary Password. I was quite shocked to read in bug #1261977 that the Primary Password is actually not used to encrypt the passwords, but only the salt.
I am aware this bug is related with bug #927963 and bug #1716071. But it doesn't seem to me that the seriosity of the problem has been recognized yet.

It takes a work colleague with malicious intentions only 1 minute during which his/her colleague's work computer is left unlocked to add his/her mobile device to the synced devices running Firefox (by simply scanning a QR code and clicking on "unlock device" in his/her colleague's Firefox), after which he/she gets access all of his/her colleague's passwords without any protection by the Primary Password. There's not even a password prompt asking for the Firefox Sync password if a new device is added.

This feature is completely broken in my eyes.

I did some more testing, and there is simply no secure way to prevent the syncing of passwords to other devices (and their storage without a Primary Password) with Firefox Sync. I can deselect the password syncing in the sync options on my desktop computer on which I store all my passwords, so no passwords get synced to my mobile devices. However, on my mobile devices I can simply switch ON the syncing of the passwords in the Sync settings, which automatically toggles the same setting on my desktop Firefox, and within minutes all passwords from my desktop computer are available on the mobile device without any password prompt. This makes losing your mobile device with Firefox Sync enabled a huge security risk if passwords are stored on ANY synced device.

When I set up a Primary Password, I do this under the assumption that if my device gets stolen, the thief has no way to access the passwords that are secured with it, at least not easily.

This is still true: if your device gets stolen the primary password protects the stored passwords. That is not the scenario you have described above. In your scenario the victim has unlocked the cash register and walked away. It's a plausible scenario because people don't think of their unlocked computer as valuable as an unlocked cash drawer, but it's the case nonetheless.

This is documented behavior [see the bottom of this comment] so keeping the bug hidden is not protecting anyone from abuse. On the contrary, raising the issues might help more people be aware and protect themselves if necessary. Bugs are not the place for advocacy and discussion, though, so hopefully the password folks can add a pointer to a better place to discuss this online (mailing list? https://discourse.mozilla.org forum? https://chat.mozilla.org live chat?)

It takes a work colleague with malicious intentions only 1 minute during which his/her colleague's work computer is left unlocked to ...

You can finish that sentence with a zillion different bad things, and that's been true for 40+ years (yes, before PCs). The problem in that scenario is inadequate physical security in an untrustworthy environment.

This isn't a barrier in practice, but it does assume the victim a) is logged into Sync (you can't connect another device if you're not), and b) has entered their primary password for the session. It's possible to log out of the primary password but very obscure and unlikely to be discovered. It's pretty easy to log out of sync from the menu or the avatar on the toolbar, but still more hassle than closing the laptop, mousing to a screen-lock "hot corner", or Window-key+L on Windows or ^⌘Q on Mac.

When the attacker signs up their new device Firefox Accounts will mail a notification to you. It will also show up as a connected device on your sync "Manage Account" page. Of course a competent attacker might disconnect again before you check your account, and might use the stolen passwords to access and delete mail.

The current behavior is described on our support site

This means the Primary Password is specific to a single device and not your Firefox account. Each device can have a different (or no) Primary Password, and they are not synced between devices.

Tip: Increase protection by enabling a Primary Password on each device. See Use a Primary Password to protect stored logins and passwords.

Group: firefox-core-security
Component: Untriaged → Password Manager
Product: Firefox → Toolkit

This is still true: if your device gets stolen the primary password protects the stored passwords. That is not the scenario you have described above.

In the second procedure to reproduce I describe how the password protection can be removed: Log out from Sync, reset the Primary Password, log back in to sync, let it sync, and all stored login passwords are freely accessible.

Tip: Increase protection by enabling a Primary Password on each device. See Use a Primary Password to protect stored logins and passwords.

That doesn't help at all, as the Primary Password can be bypassed within a few minutes with the second procedure to reproduce I described in the ticket description.
Setting a Primary Password is therefore completely useless. It's giving users a feeling of security that is in no way justified.

(In reply to Daniel Veditz [:dveditz] from comment #2)

Thanks for clarifying that. It is something that has been itching me for some time, too. But maybe you can take this as a reminder that it might be a good idea to clarify the security concept of storing passwords in one document for reference.

And while we are at it:

How are passwords protected while they are stored in my account? Are they "end-to-end" encrypted - meaning that the key contains a secret that always remains in the owners domain and is never shared with Mozilla? This here suggests that they are not:

"Sync then re-encrypts them based on your Firefox account password, then sends them to Sync servers."

My Firefox account password is something I share with Mozilla, meaning they have access to it. Am I missing something?

ju

Hello there!

The best place to talk about new features or ideas is https://connect.mozilla.org .

Here are some details on How Firefox Sync keeps your data safe even if TLS fails. We do not have access to your password or decrypted data, your password is used locally to derive encryption key which is used to encrypt data. That also means you must remember your password, we won't be able to reset it for you.

Primary Password is a deterrent feature, it can prevent quick attacks when user leaves their system unlocked and malicious actor runs in to do harm. Personally I think we should call it "Device Password" because as Daniel explained before this is used to protect device data only. Given the ways modern OSes are designed, user can't leave their system unlocked and expect safety. Once malicious actor can run code under victim's user, it's game over.

The best way to protect your Firefox Account data is to Secure your Firefox Account with two-step authentication. That way attacker can't get to victim's data without going through 2FA.

Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → INVALID

Use the method described in the Help pages to reset the Primary Password (chrome://pippki/content/resetpassword.xhtml, click on "Reset":

I am shocked and appalled our support folks would recommend that horrible hack. That's looks like leftover orphaned (and broken!) Netscape 6.0/SeaMonkey code. If we need that functionality we should support it properly

(In reply to Peter from comment #3)

if your device gets stolen the primary password protects the stored passwords. That is not the scenario you have described above.

In the second procedure to reproduce I describe how the password protection can be removed: Log out from Sync, reset the Primary Password, log back in to sync, let it sync, and all stored login passwords are freely accessible.

The primary password protects locally stored passwords. Your Sync login protects your cloud data (passwords, but also a lot more). In your second scenario how did the attacker learn the Sync password? That's where the security problem happened. Even safer would be to enable 2FA on your Firefox Account just in case someone did manage to see you type in the Sync password somewhere.

That doesn't help at all, as the Primary Password can be bypassed within a few minutes with the second procedure to reproduce I described in the ticket description. Setting a Primary Password is therefore completely useless. It's giving users a feeling of security that is in no way justified.

You can use a primary password without using Sync, and you can use Sync without a primary password. If you use both then you need to keep both passwords secret. If you close Firefox and then share your computer, the primary password will keep anyone from stealing your passwords from your computer. If you don't have a primary password then someone with access to your computer could access your passwords, including your Sync password if you use Sync. If you do have a primary password but you have unlocked it and left Firefox running then it's functionally pretty much like not have a primary password.

You can, technically, log out of your primary password without having to shut down Firefox:

  • in Settings (about:preferences) search for "Security Devices" and click that button
  • Click on "Software Security Device" in the left column
  • click the "Log Out" button

If you use Sync and do that then Firefox will pester you every few minutes to enter the primary password again. You can hit ESC to dismiss it, but you will eventually get annoyed and log in again.

(In reply to Juergen Schmidt from comment #4)

But maybe you can take this as a reminder that it might be a good idea to clarify the security concept of storing passwords in one document for reference.

I'm not sure what you mean by "storing ... in one document".

"Sync then re-encrypts them based on your Firefox account password, then sends them to Sync servers."

My Firefox account password is something I share with Mozilla, meaning they have access to it. Am I missing something?

"based on" is doing a lot of work there. When you enter your Firefox Account password in Firefox it is not directly posted to the Mozilla server, it stays right there in your Firefox. We use a "key stretching" function on your password to generate a strong key, and then that key is what our Firefox Account servers think your password is. This uses "one-way" cryptography that is impossible to reverse to recover the original password other than the brute-force approach of trying every combination -- an attack that is impractical if you've chosen a strong password.

We use a different set of parameters to the key stretching function to generate a data key that protects the end-to-end encryption. There is no way to obtain the data key from the login key or vice versa: you need to start from the password or passphrase you enter and that is never sent to our servers.

(In reply to Daniel Veditz [:dveditz] from comment #7)

I'm not sure what you mean by "storing ... in one document".

To clarify: I suggest one public document

Security of the (syncronised) Firefox password store

that describes the architecture including the general security guarantees you are giving, the existing security boundaries and the involved tradeoffs -- and of course the concept how you implement all those. This requires some work but it's an invaluable resource for everybody who needs some in depth understanding of what is going on, but not all the gory details of the code. I am talking about 2-3 pages - not more.

But perhaps this already exists and I just did not find it ...

thanks for your work!

While my comment #8 is invalid, I still think that the process of decrypting and re-encrypting of passwords multiple times by Firefox Sync (once when the passwords are synced from one device to the Firefox cloud, a second time when the passwords are synced from Firefox cloud to another device) is a flawed design and opens up many unwanted and unforeseeable security holes.

I am aware that an open browser with an unlocked password store is susceptible to many kinds of malicious action, alright. Let me therefore emphasize that my main concern is the security of the stored passwords in case one of my devices gets stolen. In my eyes it should at least be very difficult for a thief to break or bypass the Primary Password and access the saved logins. Not ensuring this can cause huge trouble to users, as the list of stored passwords can be long, with hundreds of saved logins.

So let me point out one scenario in which the assumed security can be breached with ease:
A user saves his passwords only in the Firefox instance on his desktop computer, protects them with a secure Primary Password and sets up Sync to his mobile devices. In order to reduce his risks he explicitly selects only the bookmarks to be synced between his devices. On his mobile phone he doesn't store any passwords and therefore doesn't set a Primary Password. Now he loses his phone. The thief manages to break the user authentication of the phone's OS and notices that Firefox is connected to Firefox Sync. Then he simply checks the checkbox to also sync the logins/passwords in addition to the bookmarks. There is no request for a 2FA code nor a request to enter the Firefox Sync Password when checking it. The thief then simply needs to wait until his victim goes online with Firefox on his desktop computer again, then all passwords stored there will be synced to the mobile phone and decrypted on the way.
Of course you could say that the user should have set up a Primary Password on all his devices or that he should have removed the stolen device from Sync immediately when noticing the theft. But it's rather unexpected behaviour for most users that the settings of the objects that are synced can be changed on any connected device, and especially that passwords that are synced in this unintended manner lose their protection by the Primary Password.

You could of course fix this by implementing additional rules in the Sync (a password prompt and the request of a 2FA code in case additional items are selected to be synced), but can you be sure you're not missing more loopholes that allow to trick the system?

I strongly suggest to abandon the decryptions and re-encryptions of the password vaults during Sync.

It's not even possible to set up a Primary Password on FF Mobile since version 79.0.5 and is only protected by the phone password, which can be fairly easy to overcome.
Guys, this whole implementation is seriously bad. Sorry to insist.

You need to log in before you can comment on or make changes to this bug.