Join us and the lead editor of IRL, Mozilla's multi-award-winning podcast, for a behind-the-scenes look at the pod and to contribute your ideas for the next season, themed: "AI and ME." Mark your calendar and join our Community Call on Wednesday, Aug 7, 17:00–17:45 UTC. See you there!

Sykje yn Support

Mij stipescams. Wy sille jo nea freegje in telefoannûmer te beljen, der in sms nei ta te stjoeren of persoanlike gegevens te dielen. Meld fertochte aktiviteit mei de opsje ‘Misbrûk melde’.

Mear ynfo

Dizze konversaasje is argivearre. Stel in nije fraach as jo help nedich hawwe.

Secure primary password replaced by insecure PIN

  • 3 antwurd
  • 1 hat dit probleem
  • 6 werjeftes
  • Lêste antwurd fan Paul

more options

Why has the primary password function (in my case fairly secure) been replaced with the very insecure Android PIN. More importantly, how does Firefox Android decrypt saved passwords without the primary password, or are they now stored in an unencrypted form?

Why has the primary password function (in my case fairly secure) been replaced with the very insecure Android PIN. More importantly, how does Firefox Android decrypt saved passwords without the primary password, or are they now stored in an unencrypted form?

Alle antwurden (3)

more options

Hi

Thank you for your question.

The primary password feature was removed in the update as it was not as secure as we would have liked it to have been. Your login in credentials are stored in an encrypted form and in such a way that apps outside of Firefox for Android are unable to access them. Naturally, I recommend that your secure your device with the built in device encryption and passwords.

more options

Hi Seburo,

Thanks for the informative reply and I understand the reasoning for the change based on security issues. However, for myself, it had the unfortunate result of, post automatic app update, removing my secure 16_character password and replacing it with a relatively insecure 4_digit PIN. If this had occurred with the Windows version, it probably would not have had the same impact. OS versions for PCs tend to have better password complexity. (Although, thinking that you have two level security of OS/Firefox is also downgraded.) Phones, although possibly as powerful as a laptop, have a different usage model and trying to have the equivalent of a 16_character password for my Android phone would make it difficult to use (for me). Unfortunately I think the only solution for me is to remove Firefox from my Android phone. Cheers, Brent.

more options

Thank you for your feedback.