Closed Bug 713164 Opened 14 years ago Closed 14 years ago

"show saved password" function is very dangerous

Categories

(Firefox :: Security, defect)

8 Branch
x86_64
Windows 7
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 394533

People

(Reporter: will.shenzhen.gd, Unassigned)

Details

Attachments

(1 file)

User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:8.0) Gecko/20100101 Firefox/8.0 Build ID: 20111104165243 Steps to reproduce: 1. Open firefox; 2. Select Options > Security > Saved Password; 3. Click Show Passwords button Actual results: All my passwords shown. Expected results: "Show Passwords" button should not exist. This is very severe security issue! If anyone who has the opportunity to log on my computer would crack all my passwords! Please cancel this button and its function.
Will, If you enable a master password under Options -> Security, then your local password file will be encrypted and you will be prompted to enter your master password each time you want to show a password value. If you do set a master password, you must never forget it since you will lose all of your saved passwords if you reset it. I believe this is functioning as intended, so I'll mark it invalid but want to thank you for your but report.
Group: core-security
Status: UNCONFIRMED → RESOLVED
Closed: 14 years ago
Resolution: --- → INVALID
See how good this function is ! You have detected that your passwords are not secure without a masterpassword. We could remove the menu entry but that wouldn't secure your passwords. Someone could just steal 2 files from your Firefox userprofile and extract the passwords later.
Resolution: INVALID → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: