GetDotted Domains

Viewing Thread:
"FireFox (& Chrome) - view all saved passwords! - Master Password 'heads up'"

The "Freeola Customer Forum" forum, which includes Retro Game Reviews, has been archived and is now read-only. You cannot post here or create a new thread or review on this forum.

Fri 11/11/11 at 13:14
Moderator
"Are you sure?"
Posts: 5,000
Security [i]heads up[/i]

I use FireFox but not as my main browser, and I've just come across what may be old news to seasoned FF users but it surprised me!

I like the way FF offers to remember passwords - it gives 3 options against Internet Explorer's 2.
To SAVE a password or not or just 'not now' which gives you a chance to decide later which works well.

I naively thought my saved passwords would be safely encrypted and stored away from prying eyes - but I was wrong!

In IE saved passwords are encrypted but can be easily converted back to plain text using freely available 'tools' - but it's not something everyone would have access to.

But with FF (for me by default) all my userids and passwords can be easily viewed in plain text with just a few clicks.

Using:
Options > Security Tab > Saved Passwords... > Show Passwords

This displays a dialogue box asking 'if you are sure' - click this then ALL your saved userids/passwords are there to see in readable format!


Master Password
In the above Security Tab there is an option to use something called Master Password. This is a password just for the FF password manager. Using this means that any tom, dick or harry can't view your saved user credentials without knowing this additional Master Password. But it also means that the first time you visit a site that uses a saved password you will be asked for your Master Password to proceed. You only have to enter this once for each session - i.e. If you restart FF you would be asked again.


As I mentioned many FF users will no doubt already be aware of how this works as it looks like it's always been this way - but for me it was a shock to find out.

There are FF hacks which enable you to remove the 'View Passwords' button etc. - but it's not a real answer as the hack can just be reversed.

Ever since FF launched people (often MS bashers) have been saying use FireFox it's so much more secure etc. etc. - makes you wonder ;¬)

[s]Hmmm...[/s]
Sat 10/08/13 at 21:44
Regular
Posts: 595
There's always Roboform.

Neil
Wed 07/08/13 at 15:39
Moderator
"Are you sure?"
Posts: 5,000
Just bumping this old thread...

The Guardian Tech on Twitter has been chatting about this today and it's surprising (or not!) how many people are shocked when they realise people can view all their saved passwords if they have access to a PC.

Along similar lines this YouTube Video is worth a look.
It's a good 'party piece' to show someone how all their Chrome/FF/IE passwords can be revealed!


[s]Hmmm...[/s]
Thu 17/11/11 at 11:07
Moderator
"Are you sure?"
Posts: 5,000
I've just looked at Google's Chrome browser and found this is even worse - website/userid/passwords all on show in plain text and there's no 'Master Password' option! :¬(


Options > Personal Stuff > Manage Saved Passwords
Click on required account and then the Show button.


So for any Chrome users out there who don't work in a nice cosy home office like me - careful if you leave your PC unlocked in a shared environment if you save userids and passwords!

Also might be worth thinking about if you take you PC to be repaired down the local Computer Shop or leave a stranger to fix your PC while you are out of the room...



[s]Hmmm...[/s]
Fri 11/11/11 at 14:53
Regular
"Feather edged ..."
Posts: 8,536
Nice 'heads up' Hmmm. Like you, I don't use FF as my main browser only as a means to an end - BF3 requires an 'updated browser' which IE8 isn't - but a surprising 'find'!

I'll recommend the thread for a GAD - readable, straightforward and informative :¬D
Fri 11/11/11 at 13:14
Moderator
"Are you sure?"
Posts: 5,000
Security [i]heads up[/i]

I use FireFox but not as my main browser, and I've just come across what may be old news to seasoned FF users but it surprised me!

I like the way FF offers to remember passwords - it gives 3 options against Internet Explorer's 2.
To SAVE a password or not or just 'not now' which gives you a chance to decide later which works well.

I naively thought my saved passwords would be safely encrypted and stored away from prying eyes - but I was wrong!

In IE saved passwords are encrypted but can be easily converted back to plain text using freely available 'tools' - but it's not something everyone would have access to.

But with FF (for me by default) all my userids and passwords can be easily viewed in plain text with just a few clicks.

Using:
Options > Security Tab > Saved Passwords... > Show Passwords

This displays a dialogue box asking 'if you are sure' - click this then ALL your saved userids/passwords are there to see in readable format!


Master Password
In the above Security Tab there is an option to use something called Master Password. This is a password just for the FF password manager. Using this means that any tom, dick or harry can't view your saved user credentials without knowing this additional Master Password. But it also means that the first time you visit a site that uses a saved password you will be asked for your Master Password to proceed. You only have to enter this once for each session - i.e. If you restart FF you would be asked again.


As I mentioned many FF users will no doubt already be aware of how this works as it looks like it's always been this way - but for me it was a shock to find out.

There are FF hacks which enable you to remove the 'View Passwords' button etc. - but it's not a real answer as the hack can just be reversed.

Ever since FF launched people (often MS bashers) have been saying use FireFox it's so much more secure etc. etc. - makes you wonder ;¬)

[s]Hmmm...[/s]

Freeola & GetDotted are rated 5 Stars

Check out some of our customer reviews below:

Continue this excellent work...
Brilliant! As usual the careful and intuitive production that Freeola puts into everything it sets out to do, I am delighted.
I've been with Freeola for 14 years...
I've been with Freeola for 14 years now, and in that time you have proven time and time again to be a top-ranking internet service provider and unbeatable hosting service. Thank you.
Anthony

View More Reviews

Need some help? Give us a call on 01376 55 60 60

Go to Support Centre
Feedback Close Feedback

It appears you are using an old browser, as such, some parts of the Freeola and Getdotted site will not work as intended. Using the latest version of your browser, or another browser such as Google Chrome, Mozilla Firefox, or Opera will provide a better, safer browsing experience for you.