Join us and the lead editor of IRL, Mozilla's multi-award-winning podcast, for a behind-the-scenes look at the pod and to contribute your ideas for the next season, themed: "AI and ME." Mark your calendar and join our Community Call on Wednesday, Aug 7, 17:00–17:45 UTC. See you there!

Sykje yn Support

Mij stipescams. Wy sille jo nea freegje in telefoannûmer te beljen, der in sms nei ta te stjoeren of persoanlike gegevens te dielen. Meld fertochte aktiviteit mei de opsje ‘Misbrûk melde’.

Mear ynfo

Dizze konversaasje is argivearre. Stel in nije fraach as jo help nedich hawwe.

Why can I still download new emails after changing my pword via the web site of my email provider, but have not yet changed it in Thunderbird?

  • 4 antwurd
  • 1 hat dit probleem
  • 1 werjefte
  • Lêste antwurd fan Dashour

more options

Normally, when I change my email password, I do it on the email providers web site. Once the password is changed that way, I cannot download email into thunderbird until I have also changed the password that Thunderbird uses to access my email account. This is usually done via a pop up window in thunderbird that asks me for the password.

However, I have just changed my email password as normal, but thunderbird can still download my email from that account without asking at all the new password, and when I checked in "saved passwords" the OLD password is still listed (but not, of course, the new one)

I have repeated tested out the new password on my providers web site, and indeed the new password now works, and the old password does not work - except in Thunderbird, where it continues to work. Why?

Normally, when I change my email password, I do it on the email providers web site. Once the password is changed that way, I cannot download email into thunderbird until I have also changed the password that Thunderbird uses to access my email account. This is usually done via a pop up window in thunderbird that asks me for the password. However, I have just changed my email password as normal, but thunderbird can still download my email from that account without asking at all the new password, and when I checked in "saved passwords" the OLD password is still listed (but not, of course, the new one) I have repeated tested out the new password on my providers web site, and indeed the new password now works, and the old password does not work - except in Thunderbird, where it continues to work. Why?

Keazen oplossing

dashour said

Ok Matt many thanks for that answer. Uhm, is this something I should be concerned about?

No.

My main concern was that my old password could still be used by somebody - but this sounds like that's not the case, right?

Right.

Dit antwurd yn kontekst lêze 👍 1

Alle antwurden (4)

more options

My guess is you are using Oauth2.0 to authenticate. It uses token created when you enter your password the first time and will continue to work until the provider revokes them in some cases for ever.

The Oauth folks have information on their web site https://www.oauth.com/oauth2-servers/access-tokens/access-token-lifetime/

Exactly what "model" is in use in your case I have no idea.

Google discuss their implementation here https://developers.google.com/identity/protocols/OAuth2UserAgent#validate-access-token As that is the main use of Oauth in Thunderbird I am assuming it is their implementation.

more options

Ok Matt many thanks for that answer. Uhm, is this something I should be concerned about? My main concern was that my old password could still be used by somebody - but this sounds like that's not the case, right? Thanks.

more options

Keazen oplossing

dashour said

Ok Matt many thanks for that answer. Uhm, is this something I should be concerned about?

No.

My main concern was that my old password could still be used by somebody - but this sounds like that's not the case, right?

Right.

Bewurke troch Matt op

more options

Many thanks Matt. A quick reply, for free, it doesn't get better than that. Cheers.