Closed Bug 1854759 Opened 2 years ago Closed 2 years ago

Security breach of passwords

Categories

(Firefox :: Security, defect)

Firefox 117
defect
Points:
?

Tracking

()

RESOLVED INVALID

People

(Reporter: vetulusmontanis, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/117.0
Firefox for Android

Steps to reproduce:

  1. Install Google Chrome.
  2. Store password in Google Chrome.
  3. Install Firefox.
  4. Create new firefox account (can be different from the chrome actual)
  5. Import passwords from Chrome to Firefox.
  6. Chrome passwords are now transfered to a different account.

Actual results:

I downloaded firefox because i like it and i decided to import my passwords to firefox. It did not ask me of any credentials or verification that i was not just abusing a process.

Expected results:

A form of verification that i am the owner of the passwords should appear to avoid any dupes to any actors which are not myself.

This allows anyone with access to the desktop to copy and sync all passwords from chrome to firefox without any form of verification of authorization.

Points: --- → 15
Component: Untriaged → Security
OS: Unspecified → All
Hardware: Unspecified → All

There is a possibility for the issue to be reversed - as in having Chrome collect passwords from Firefox without any form of authentication. This could also be automated by a malicious user/software which impersonates itself as a browser and "collects" the data needed - without any form of security awareness being raised.

Points: 15 → ?

Thanks for sharing your concern with us!

Importing passwords from Chrome to Firefox or from Firefox to Chrome is possible when user runs on the same OS account. If an attacker is able to access unlocked OS account then there is not much any app can do.

Group: firefox-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 2 years ago
Resolution: --- → INVALID

(In reply to Sergey Galich [:serg] from comment #3)

Thanks for sharing your concern with us!

Importing passwords from Chrome to Firefox or from Firefox to Chrome is possible when user runs on the same OS account. If an attacker is able to access unlocked OS account then there is not much any app can do.

Well, for one it can disable the import and export of passwords without an additional layer of authentication. The process is already in the webbrowser for when you want to view the passwords - then you have to authenticate again to prove that you are the user. This way - you dont have to and you can sync everything to a different server.

But ok - if you say that this is not an issue then i will just not use firefox.

(In reply to vetulusmontanis from comment #4)

Well, for one it can disable the import and export of passwords without an additional layer of authentication. The process is already in the webbrowser for when you want to view the passwords - then you have to authenticate again to prove that you are the user. This way - you dont have to and you can sync everything to a different server.

All of that is happening on unlocked OS account, meaning that user have already authenticated.
Attacker that has access at this point will be able to install keyloggers, steal files, steal existing authentication tokens and more. Asking to authenticate user again will only create sense of false security.

But ok - if you say that this is not an issue then i will just not use firefox.

I respect your choice, sorry to see you go. Whatever browser you'll pick, please make sure you lock your system when you are not using it.

You need to log in before you can comment on or make changes to this bug.