Closed
Bug 381700
Opened 18 years ago
Closed 18 years ago
Security issue: Same passwords for multiple accounts on the same site
Categories
(Toolkit :: Password Manager, defect)
Tracking
()
RESOLVED
WORKSFORME
People
(Reporter: nileshhiray, Unassigned)
Details
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
Say you have multiple accounts on the same website with the *same* passwords and you chose to remember all of them.
I have this situation for two of my yahoo.co.in accounts.
Now when i log in to mail.yahoo.com, my mail account name field is empty while the password field gets filled in :)
As i own both the accounts its not an issue for me. Very rare, but certainly needs to be fixed sometime.
Haven't tried this with any other site. So a remote chance is that it has to do something with yahoo. (i dont think so though)
Reproducible: Always
Steps to Reproduce:
1. Create multiple accounts in the same site with the same passwords
2. Remember passwords for both
3. open the login page
(havent tried this again. so not sure its reproducible)
Actual Results:
Password is printed (in asterisks of course) and user name field is empty
Expected Results:
Either of the username should be displayed OR empty
Havent really tried reproducing this multiple times. So not sure if its a glitch.
Its a very rare event.
Comment 1•18 years ago
|
||
Not a security sensitive bug.
I can't reproduce this bug using the form at bug http://gavinsharp.com/tmp/form.html. If I submit the form with two different user names, but the same password, and remember both, when I next load the page both fields are empty, and the autocomplete dropdown contains the two user names.
Group: security
Comment 2•18 years ago
|
||
(I was testing a recent 1.8 branch build on the Mac)
Well, I could not go through the http://gavinsharp.com/tmp/form.html you mentioned.
Well, you should try on a similar configuration IMO. For example, I did not have this problem in my firefox browser on a bsd machine. Also, I still have the browser in this state. Will any information from the browser help you guys investigate the cause?
Comment 4•18 years ago
|
||
(In reply to comment #3)
> Well, I could not go through the http://gavinsharp.com/tmp/form.html you
> mentioned.
You can't reach the site at all? It seems to work for me now, perhaps it was down for a bit? Could you try again?
> Will any information from the browser help you guys investigate the cause?
Figuring out the steps needed to reproduce the problem consistently, from a fresh profile, would be more useful at this stage, I think.
Comment 5•18 years ago
|
||
Need more information to diagnose the problem here. if you can reproduce with a fresh, clean profile, please reopen with the specific steps to reproduce.
Status: UNCONFIRMED → RESOLVED
Closed: 18 years ago
Resolution: --- → INCOMPLETE
Updated•18 years ago
|
Resolution: INCOMPLETE → WORKSFORME
Summary: Security issue: Same passwords for muliple accounts on the same site → Security issue: Same passwords for multiple accounts on the same site
Assignee | ||
Updated•17 years ago
|
Product: Firefox → Toolkit
You need to log in
before you can comment on or make changes to this bug.
Description
•