[Bug 250817] [NEW] bypass master-pw by beeing quick

hollunder hollunder at gmx.at
Tue Jul 22 13:33:35 UTC 2008


Public bug reported:

Binary package hint: firefox-3.0

Ubuntu Studio Hardy Heron
Package Firefox 3.0+nobinonly-0ubuntu0.8.04.1


Situation:
A Master-pw is set, it is required to enter it once in a session when there is a webpage for which I safed he log-in information. The 'secure login' add-on is installed, for opera-style 'safed login information gets entered when you press the button, instead of right away'.


What should happen:
I start firefox, lots of pages get loaded from the last session. I don't wait for all the pages to load, instead I go to a tab with a page with a log-in. 

I hit the 'secure log-in'-button. The request for the master password
pops up. After I entered the master-pw I get logged in OR need to hit
the 'secure-log-in' button again to get logged in.


What happens:

I hit the 'secure log-in'-button, and get logged in. At some point, the
request for the master password pops up. At this point of time I'm
already logged in and the master-pw request is useless.


I didn't test it further but I think that there are possibly other cases where the master-pw can be bypassed in a similar manner.

** Affects: firefox-3.0 (Ubuntu)
     Importance: Undecided
         Status: New

-- 
bypass master-pw by beeing quick
https://bugs.launchpad.net/bugs/250817
You received this bug notification because you are a member of Mozilla
Bugs, which is subscribed to firefox-3.0 in ubuntu.




More information about the Ubuntu-mozillateam-bugs mailing list