emptying all Passwords locks you out from Firefox Sync



Cloud Services
Firefox Sync: UI
5 years ago
5 years ago


(Reporter: Ruben, Unassigned)


Firefox Tracking Flags

(Not tracked)


(Whiteboard: [qa?])



5 years ago
User Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:21.0) Gecko/20100101 Firefox/21.0 (Beta/Release)
Build ID: 20130512194354

Steps to reproduce:

I used Firefox Sync to synchronize my passwords with my other Computer. Now I want to delete only the password Data locally and from Sync.

I pressed on "Delete All Passwords" in the Password Manager (which took several minutes to complete, which is another Bug, but it worked in the end). After I checked again, if the passwordlist is really empty, I closed firefox and reopened it.

Actual results:

After deleting all passwords, Sync isn't working anymore.
It sais in a black Box at the bottom: Sync - Error at synchronisation: invalid username or password. ( have it only in german: "Sync - Fehler bei der Synchronisation: Ungültiger Benutzerkonto-Name oder Passwort. ...")

Expected results:

the empty password-list should be synchronized to my other devices, so they will have an empty list too

Comment 1

5 years ago
This is critical, because if the other device got stolen now I would have no possibility to delete my saved passwords in the Passwordmanager on the other device anymore
Severity: normal → major
Component: Untriaged → Security

Comment 2

5 years ago
actually it is not a "Security-Sensitive Core Bug" (I misunderstood the checkbox)  this bug shouldn't be hidden, please reveal it to public

Comment 3

5 years ago
A solution would have been bug 881177
See Also: → bug 881177
Group: core-security

Comment 4

5 years ago
could it be, that this only happens if you delete ALL passwords, including that one for "chrome://weave"?
Component: Security → Firefox Sync: UI
Product: Firefox → Mozilla Services
Version: 21 Branch → unspecified

Comment 5

5 years ago
My gut feeling is this has come up before. Richard?
Flags: needinfo?(rnewman)
I have seen "something" like this in the past if I clear passwords in my Prefs (not specifically Password Manager - instead I used Prefs > Privacy > History). On first attempt to sync I get login/password error (because my sync password is no longer being saved).
But, once I set the password again, all is fine.
Not sure if we are talking the same symptoms/cause here, though...
Whiteboard: [qa?]
Multiple problems:

* Clearing passwords also clears your Sync passwords. Bug 553400.
* Clearing data doesn't necessarily propagate to other devices. Bug 578694 might be your jumping-off point.
* You really want a device management capability. Sync doesn't have that.

Duping this to the first.
Last Resolved: 5 years ago
Flags: needinfo?(rnewman)
Resolution: --- → DUPLICATE
Duplicate of bug: 553400
See Also: bug 881177

Comment 8

5 years ago
bug 553400 is related, but it is not a duplicate of this: that bug is about the option "clear saved passwords on quit"

Here I talk about the option inside the password manager to remove all passwords. A solution would be, if that would clear all passwords *except* the sync-password.
Resolution: DUPLICATE → ---
(In reply to Ruben from comment #8)
> bug 553400 is related, but it is not a duplicate of this: that bug is about
> the option "clear saved passwords on quit"

Those are fundamentally the same thing.

The root cause is that credentials for the thing that syncs your passwords are stored in the same box as the passwords.

This is a duplicate because addressing one bug will directly address the other, and they have the same root cause.
Last Resolved: 5 years ago5 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 553400
You need to log in before you can comment on or make changes to this bug.