Closed Bug 2003105 Opened 9 months ago Closed 9 months ago

Primary password Bypass

Categories

(Thunderbird :: Security, defect)

Thunderbird 140
defect

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 1566458

People

(Reporter: wildzekat, Unassigned)

Details

Steps to reproduce:

I (accidentally) opened thunderbird on my debian, then closed my master password prompt.
After it reopened, I closed it again.
Then, for testing, I clicked on my mail accounts and opened random mails, without entering a password at any time.

Actual results:

It reopened, after being closed a second time it still opened thunderbird. it asks me for the password every time I click on a button in the mail accounts, but that seemingly does not stop me from reading mails.

Expected results:

The app shouldnt even open after entering wrong / no password.

I am currently running the package thunderbird 1:140.5.0esr-1~deb12u1 from the debain 12 apt database.
In prior versions, when closing the password prompt without entering the password, the process closed and didnt open my mail program.

Thanks. But the purpose of primary password has never been to prevent access to the application or the data stored therein, other than the passwords and other "secret" data.

Please see https://mzl.la/3vQohyn

Group: mail-core-security
Status: UNCONFIRMED → RESOLVED
Closed: 9 months ago
Duplicate of bug: 1566458
Resolution: --- → DUPLICATE
Summary: Masterpassword-Bypass → Primary password Bypass

(In reply to Wayne Mery (:wsmwk) from comment #2)

Thanks. But the purpose of primary password has never been to prevent access to the application or the data stored therein, other than the passwords and other "secret" data.

Please see https://mzl.la/3vQohyn

*** This bug has been marked as a duplicate of bug 1566458 ***

Does this mean Thunderbird NOT starting and quitting instead when not entering the primary password has been the real bug here?
(by the way, yes, I understand these limitations. I do not intent to use this in an attempt to prevent data stealing, it only adds a time consuming annoyance for potential screen peekers.)

You need to log in before you can comment on or make changes to this bug.