Closed Bug 546776 Opened 15 years ago Closed 12 years ago

Allow secure storage of Sync/Firefox Account credentials if "save passwords" and/or master password are disabled

Categories

(Firefox :: Sync, defect, P2)

defect

Tracking

()

RESOLVED DUPLICATE of bug 553400

People

(Reporter: mconnor, Unassigned)

Details

(Keywords: uiwanted, Whiteboard: uiwanted)

As a fairly strong rule, we don't want to offer a login UI on each startup. Frequency of password entry is inversely tied to password strength, and it's worse if there's multiple passwords, so a login UI will lead to users using weaker passwords, in general. If users are not using password manager for web pages, but want to use Weave, we should special case these users as follows: * Tell them explicitly that we will store the passwords in the password manager * Make them opt _out_ of using a master password (or possibly force them to use the master password) If their MP is weak, but the password/passphrase remain strong, that's less bad, because that's just protecting against local attacks, and there's other mitigations for that, but weak passphrase/password exposes users _far_ worse, and we shouldn't create UI that will move users in that direction.
OS: Mac OS X → All
Hardware: x86 → All
Target Milestone: 1.2 → 2.0
Target Milestone: 2.0 → Future
To be clear, this is a UX question for what happens if password saving is disabled (Remember passwords for sites).
Whiteboard: uiwanted
Connor, is this still valid?
Keywords: uiwanted
Morphing this into something more useful.
Priority: -- → P2
Summary: if remember passwords is disabled, special-case setup to encourage/force master password → Allow secure storage of Sync/Firefox Account credentials if "save passwords" and/or master password are disabled
Target Milestone: Future → ---
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Component: Firefox Sync: UI → Sync
Product: Cloud Services → Firefox
You need to log in before you can comment on or make changes to this bug.