Open Bug 1458709 Opened 7 years ago Updated 2 years ago

lastpass.com bypasses container isolation

Categories

(Core :: DOM: Security, defect, P3)

61 Branch
defect

Tracking

()

UNCONFIRMED

People

(Reporter: jgbailey, Unassigned)

References

(Blocks 1 open bug)

Details

(Whiteboard: [domsecurity-backlog1])

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:61.0) Gecko/20100101 Firefox/61.0 Build ID: 20180502100112 Steps to reproduce: I have multi-factor authentication enabled on my lastpass.com account. 1. In a new container, go to lastpass.com and log in. 2. Enter a multi-factor authentication code at the prompt and select the 'trust this computer for 30 days' checkbox. 3. After logging in, close the tab. 4. Open a new container and go to lastpass.com 5. Log in. Actual results: You are not prompted to enter a multi-factor code on the second login attempt, even though you are in a new container. Expected results: I should have been prompted to enter a code. I would not expect whatever state the 'trust this computer' checkbox sets to persist across containers.
Component: Untriaged → DOM: Security
Product: Firefox → Core
Priority: -- → P3
Whiteboard: [domsecurity-backlog1]
Severity: normal → S3
You need to log in before you can comment on or make changes to this bug.