Show indicators on saved logins that are re-using those breached passwords
Categories
(Firefox :: about:logins, enhancement, P1)
Tracking
()
People
(Reporter: groovecoder, Assigned: jaws)
References
(Blocks 1 open bug)
Details
User Story
See updated Invision spec: https://mozilla.invisionapp.com/share/BEU7ZBJ486Y Add link to Sumo page for learn more link
Attachments
(2 files, 3 obsolete files)
In addition to showing “red alert” breach indicators on saved logins with passwords older than breaches, we should show “yellow alert” indicators on saved logins that are re-using those breached passwords.
Reporter | ||
Comment 1•5 years ago
|
||
Depends on D41096
Comment 2•5 years ago
|
||
As noted in bug 1576047, these indicators are inaccessible. I mention this here because this patch hasn't been landed yet.
Reporter | ||
Comment 3•5 years ago
|
||
Thanks for the heads-up! The "yellow alert" indicators won't be the final UI for this feature.
Updated•5 years ago
|
Reporter | ||
Comment 4•5 years ago
|
||
Updated•5 years ago
|
Updated•5 years ago
|
Updated•5 years ago
|
Comment 6•5 years ago
|
||
This is part of the vulnerable passwords project MVP.
Assignee | ||
Updated•5 years ago
|
Updated•5 years ago
|
Assignee | ||
Comment 7•5 years ago
|
||
Assignee | ||
Comment 8•5 years ago
|
||
Updated•5 years ago
|
Updated•5 years ago
|
Comment 10•5 years ago
|
||
bugherder |
Comment 11•5 years ago
|
||
I have verified this issue using the latest Nightly 76.0a1 (Build ID: 20200401212659) on Windows 10 x64, Mac 10.14, Ubuntu 18.04 x64.
- A saved login that has the same password as a breached one is marked as vulnerable.
Updated•5 years ago
|
Assignee | ||
Comment 12•5 years ago
|
||
Release Note Request (optional, but appreciated)
[Why is this notable]: Logins that share a password with a breached login will show a warning asking users to change their saved password.
[Affects Firefox for Android]: no
[Suggested wording]: A notice requesting users change their password will be shown in Firefox Lockwise (about:logins) for saved passwords that have been used with another account that was likely in a data breach.
[Links (documentation, blog post, etc)]: https://support.mozilla.org/en-US/kb/firefox-lockwise-alerts-breached-websites
Description
•