Where did you install Firefox from? Help Mozilla uncover 3rd party websites that offer problematic Firefox installation by taking part in our campaign. There will be swag, and you'll be featured in our blog if you manage to report at least 10 valid reports!

Cerca nel supporto

Attenzione alle mail truffa. Mozilla non chiederà mai di chiamare o mandare messaggi a un numero di telefono o di inviare dati personali. Segnalare qualsiasi attività sospetta utilizzando l'opzione “Segnala abuso”.

Learn More

Questa discussione è archiviata. Inserire una nuova richiesta se occorre aiuto.

When is Primary Password going to protect stored cookies? (authentication cookies in particular)

  • 1 risposta
  • 1 ha questo problema
  • 9 visualizzazioni
  • Ultima risposta di Dropa

more options

There is a wave of malware targeting authentication cookies stored on disk (e.g. recent LTT hack). It has become obvious that malware doesn't need to target stored passwords to get access to a site/account. Primary Password has solved this problem, but only for the stored passwords. The stored cookies are just as exposed as the stored passwords were, provide access to sites/accounts and bypass 2FA checks because they bypass normal login protocols.

Primary password should secure the stored cookies as well. When is this going to be implemented?

Thanks!

There is a wave of malware targeting authentication cookies stored on disk (e.g. recent LTT hack). It has become obvious that malware doesn't need to target stored passwords to get access to a site/account. Primary Password has solved this problem, but only for the stored passwords. The stored cookies are just as exposed as the stored passwords were, provide access to sites/accounts and bypass 2FA checks because they bypass normal login protocols. Primary password should secure the stored cookies as well. When is this going to be implemented? Thanks!

Tutte le risposte (1)

more options

That goes beyond what Primary password is only for Firefox account. One should check their cookie protection settings to change protection. Also one needs to insure their Security software is up to date and that it is working.