Compare Revisions
Insecure connection password warning in Firefox
Revision 194317:
Revision 194317 by AliceWyman on
Revision 207668:
Revision 207668 by peregrin.hendley on
Keywords:
Search results summary:
Firefox warns you when a login form is not secure and your information could be stolen.
Firefox warns you when a login form is not secure and your information could be stolen.
Content:
Firefox will display a lock icon with red strike-through [[Image:red strikethrough icon]] in the address bar, when a {for not fx70}login {/for}page you’re viewing does not have a secure connection. If you enter a password on such pages, eavesdroppers or attackers could steal it.
You will also see a warning message when you click inside the login box to enter a username or password.
;[[Image:Fx52insecurePW]]
'''Note:''' When you start entering your login information, the warning message can obscure the password entry box. To dismiss the warning, either press the {key Tab} key or click on the page background after you type in your username.
=What can I do if a login page is insecure?=
If the login page is insecure, check if a secure version exists by adding ''https://'' in front of the website address. You can also contact the website administrator and ask them to secure the connection.
;{for not fx70}[[Image:https_secure_lock_gree n_icon]]{/for}{for fx70}[[Image:FF70 Gray Padlock]]{/for}
{note}'''Not recommended:''' You can also continue to log in to the website even though the connection is insecure, but do so at your own risk. If you choose to log in, use a unique password that you don’t use elsewhere.{/note}
=About insecure pages=
Pages that need to transmit private information, such as credit cards, personal information and passwords, need to have a secure connection to help prevent attackers from stealing your information. ('''Tip:''' A secure connection will have {for not fx70}[[How do I tell if my connection to a website is secure?#w_green-padlock|"HTTPS" in the address bar, along with a green lock icon]]{/for}{for fx70}[[How do I tell if my connection to a website is secure?#w_gray-padlock|"HTTPS" in the address bar, along with a gray lock icon]]{/for}.)
Pages that don’t transmit any private information can have an unencrypted connection (HTTP). But, it is advised not to enter private information, such as passwords. The information you enter can be stolen over this insecure connection.
=Note for developers=
For developers looking to learn more about this warning, please see [https://developer.mozilla.org/docs/Web/Security/Insecure_passwords this page]. The page explains when and why Firefox shows this warning, and will also provide some details on how to fix the issue. For more information, see
[https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please/ this blog post] and [https://www.fxsitecompat.com/en-CA/docs/2016/insecure-password-input-warning-will-be-enabled-by-default/ this Site Compatibility document].
Firefox will display a lock icon with red strike-through [[Image:red strikethrough icon]] in the address bar when a {for not fx70}login {/for}page you’re viewing does not have a secure connection. If you enter a password on such a page, eavesdroppers or attackers could steal it.
You will also see a warning message when you click inside the login box to enter a username or password.
;[[Image:Fx52insecurePW]]
{note}'''Note:''' When you start entering your login information, the warning message can obscure the password entry box. To dismiss the warning, either press the {key Tab} key or click on the page background after you type in your username.{/note}
=What can I do if a login page is insecure?=
If the login page is insecure, check if a secure version exists by adding ''https://'' in front of the website address. You can also contact the website administrator and ask them to secure the connection.
;{for not fx70}[[Image:https_secure_lock_gree n_icon]]{/for}{for fx70}[[Image:FF70 Gray Padlock]]{/for}
{note}'''Not recommended:''' You can also continue to log in to the website even though the connection is insecure, but do so at your own risk. If you choose to log in, use a unique password that you don’t use elsewhere.{/note}
=About insecure pages=
Pages that don’t transmit any private information can have an unencrypted connection (HTTP). But, it is advised not to enter private information, such as passwords. The information you enter can be stolen over this insecure connection.
Pages that need to transmit private information (such as credit cards, personal information and passwords) need to have a secure connection to help prevent attackers from stealing your information.
{note}'''Tip:''' A secure connection will have {for not fx70}[[How do I tell if my connection to a website is secure?#w_green-padlock|"HTTPS" in the address bar, along with a green lock icon]]{/for}{for fx70}[[How do I tell if my connection to a website is secure?#w_gray-padlock|"HTTPS" in the address bar, along with a gray lock icon]]{/for}.{/note}
=Note for developers=
For developers looking to learn more about this warning, please see [https://developer.mozilla.org/docs/Web/Security/Insecure_passwords this page]. The page explains when and why Firefox shows this warning, and will also provide some details on how to fix the issue. For more information, see
[https://blog.mozilla.org/tanvi/2016/01/28/no-more-passwords-over-http-please/ this blog post] and [https://www.fxsitecompat.com/en-CA/docs/2016/insecure-password-input-warning-will-be-enabled-by-default/ this Site Compatibility document].