Closed
Bug 713164
Opened 14 years ago
Closed 14 years ago
"show saved password" function is very dangerous
Categories
(Firefox :: Security, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 394533
People
(Reporter: will.shenzhen.gd, Unassigned)
Details
Attachments
(1 file)
64.45 KB,
image/png
|
Details |
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0
Build ID: 20111104165243
Steps to reproduce:
1. Open firefox;
2. Select Options > Security > Saved Password;
3. Click Show Passwords button
Actual results:
All my passwords shown.
Expected results:
"Show Passwords" button should not exist. This is very severe security issue! If anyone who has the opportunity to log on my computer would crack all my passwords!
Please cancel this button and its function.
Comment 1•14 years ago
|
||
Will,
If you enable a master password under Options -> Security, then your local password file will be encrypted and you will be prompted to enter your master password each time you want to show a password value. If you do set a master password, you must never forget it since you will lose all of your saved passwords if you reset it.
I believe this is functioning as intended, so I'll mark it invalid but want to thank you for your but report.
Group: core-security
Status: UNCONFIRMED → RESOLVED
Closed: 14 years ago
Resolution: --- → INVALID
Comment 2•14 years ago
|
||
See how good this function is !
You have detected that your passwords are not secure without a masterpassword.
We could remove the menu entry but that wouldn't secure your passwords. Someone could just steal 2 files from your Firefox userprofile and extract the passwords later.
Updated•12 years ago
|
Resolution: INVALID → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•