Where did you install Firefox from? Help Mozilla uncover 3rd party websites that offer problematic Firefox installation by taking part in our campaign. There will be swag, and you'll be featured in our blog if you manage to report at least 10 valid reports!

Rechercher dans l’assistance

Évitez les escroqueries à l’assistance. Nous ne vous demanderons jamais d’appeler ou d’envoyer un SMS à un numéro de téléphone ou de partager des informations personnelles. Veuillez signaler toute activité suspecte en utilisant l’option « Signaler un abus ».

Learn More

When is Primary Password going to protect stored cookies? (authentication cookies in particular)

  • 1 réponse
  • 1 a ce problème
  • 9 vues
  • Dernière réponse par Dropa

more options

There is a wave of malware targeting authentication cookies stored on disk (e.g. recent LTT hack). It has become obvious that malware doesn't need to target stored passwords to get access to a site/account. Primary Password has solved this problem, but only for the stored passwords. The stored cookies are just as exposed as the stored passwords were, provide access to sites/accounts and bypass 2FA checks because they bypass normal login protocols.

Primary password should secure the stored cookies as well. When is this going to be implemented?

Thanks!

There is a wave of malware targeting authentication cookies stored on disk (e.g. recent LTT hack). It has become obvious that malware doesn't need to target stored passwords to get access to a site/account. Primary Password has solved this problem, but only for the stored passwords. The stored cookies are just as exposed as the stored passwords were, provide access to sites/accounts and bypass 2FA checks because they bypass normal login protocols. Primary password should secure the stored cookies as well. When is this going to be implemented? Thanks!

Toutes les réponses (1)

more options

That goes beyond what Primary password is only for Firefox account. One should check their cookie protection settings to change protection. Also one needs to insure their Security software is up to date and that it is working.