Update Lockwise alerts SUMO page to add info on vulnerable logins
Categories
(support.mozilla.org :: Knowledge Base Content, task, P1)
Tracking
(firefox-esr68 unaffected, firefox74 unaffected, firefox75 unaffected, firefox76 fixed)
Tracking | Status | |
---|---|---|
firefox-esr68 | --- | unaffected |
firefox74 | --- | unaffected |
firefox75 | --- | unaffected |
firefox76 | --- | fixed |
People
(Reporter: jaws, Unassigned)
References
()
Details
We will need to create a page on SUMO that can give some background on vulnerable logins in Firefox Lockwise.
Vulnerable logins are defined as a login that shares a password with a breached login in the same Firefox profile. Just as we ask a user to change their password for a website that gets breached, if that password is shared with other logins then we will ask the user to change their password on the other sites too.
This page will be linked to from within Firefox Lockwise in the "vulnerable passwords" notification.
Reporter | ||
Updated•5 years ago
|
Comment 1•5 years ago
|
||
We already have https://support.mozilla.org/1/firefox/76.0a1/Darwin/en-US/lockwise-alerts which we can probably update btw.
Reporter | ||
Updated•5 years ago
|
Comment 2•5 years ago
|
||
I think we can use this bug for updating the page for Fx76.
Reporter | ||
Updated•5 years ago
|
Comment 3•5 years ago
|
||
Hello, it seems like much of the existing content is incorrect as it's mixing up information about the monitor website (and monitor card in about:protections) with the Lockwise integration which doesn't do any lookup of passwords. Here is a quick summary of things. I'm happy to go into more detail. It would be great to fix the inaccuracies about breached passwords ASAP.
- Breached logins: We get the list of breached sites containing passwords and check two things for each login:
- Is the login's domain on the list of breached sites with passwords (or is it a subdomain of one on that list) AND is the password change date before the breach date. If a login is considered breached we store this password in a list of passwords which are vulnerable.
- Vulnerable passwords: The saved login's password matches one in the list of passwords from potentially breached logins (see above).
Neither of these use the email address or username for detection nor do they lookup the password with any database outside your computer.
Comment 4•5 years ago
|
||
I submitted a quick revision at https://support.mozilla.org/en-US/kb/firefox-lockwise-alerts-breached-websites/compare?locale=en-US&to=197971&from=195802 though feel free to improve it for 76.
Comment 5•5 years ago
|
||
I made a small edit to the revision that's pending review - see https://support.mozilla.org/en-US/kb/firefox-lockwise-alerts-breached-websites/history
Updated•5 years ago
|
I've published both of your updates. Thank you!
Comment 7•5 years ago
|
||
Resolving this, feel free to reopen if there are any other changes needed for 76
Updated•5 years ago
|
Updated•5 years ago
|
Description
•