Table of Contents
A network security researcher recently discovered that during the past 9 years, Firefox has stored user passwords with an outdated process.
The Last 9 Years Firefox Has Not Protected User Passwords Carefully Overview
Both Firefox and Thunderbird allow users to set up Master Pasword for greater security, using the SHA1 style code (which is easy to crack) over the past 9 years.
This problem was discovered by Wladimir Palant, the author of the AdBlock Plus extension. But it is worth mentioning that Wladimir mentioned this issue 9 years ago but was not overcome by Mozilla.
The password stored on Firefox turned out to be not safe at all
Palant said: 'I look at the source code and finally find the sftkdb_passwordToKey () function to switch from the password (website) to the encoded character string (key) using the SHA1 code with 1 string of your password and 1 random string. Anyone who has ever designed a login function for a website will see the problem here . '
Palant reiterated the problem and Mozilla said it would fix it when it released a new password management tool, Lockbox. In the meantime, Firefox users who want to secure their data should use a longer and more complex password.
See more:
- Why should you turn off the Autofill feature in the password manager?
- 3 golden rules to avoid fake attacks
- How to use password management Lockbox in Firefox Quantum
Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.
FAQ
Why does the Last 9 Years Firefox Has Not Protected User Passwords Carefully matter?
A network security researcher recently discovered that during the past 9 years, Firefox has stored user passwords with an outdated process.
Who may be affected by this issue?
The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.
How can users reduce the risk?
Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.
Reader Comments 0
Sign in with email or Google to join the discussion.