Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

了解更多

Master Password not carried through sync, new machine accesses to all passwords!

  • 2 回覆
  • 2 有這個問題
  • 23 次檢視
  • 最近回覆由 philipp

more options

Hi, I have a master password set on my main machine and so my passwords are securely stored and encrypted. My machine has gone in for repairs and so I used my Firefox Sync password on a new PC and when I went to my saved passwords, there was no master password and I was able to reveal all my passwords! This means if someone gets my main sync password, they will be able to reveal all my passwords simply by logging onto another machine, even though I had a master password set?? This seems very very wrong to me?

Hi, I have a master password set on my main machine and so my passwords are securely stored and encrypted. My machine has gone in for repairs and so I used my Firefox Sync password on a new PC and when I went to my saved passwords, there was no master password and I was able to reveal all my passwords! This means if someone gets my main sync password, they will be able to reveal all my passwords simply by logging onto another machine, even though I had a master password set?? This seems very very wrong to me?

所有回覆 (2)

more options

I tend not to use Firefox Sync and can not give a proper answer.

I did note someone said this was fixed, but apparently not, and our documentation therefore probably remains correct

When developing sync there were security issues and the solution used was to disable master passwords if Sync was in use. I remember following the issue at the time but do not now recall all the detail. If you disable Syncing of passwords no doubt your Master Password will work again, can you try that please ?

Are you indicating that you had a master password set, then setup Sync and set that to Sync Logins resulting in Sync disabling your Master Password ? without you realising ?


Also if using Sync on bookmarks take care. It has or had a flaw whereby it may corrupt or duplicate bookmark listings if Bookmarks are Synced, particularly if on a slow internet connection, having many bookmarks, or many changes between the different devices. I know bookmarks snapshot backups have improved in recent versions but it is probably worthwhile considering backing up bookmarks manually occasionally. if something goes wrong with the bookmarks sync it may make it easier to recover.

more options

hi, the purpose of the master password is to protecting the local password store from being read by other users or programs on the machine whereas the sync password is used to encrypt your data before they get transferred off your device.

daveonearth said

This means if someone gets my main sync password, they will be able to reveal all my passwords simply by logging onto another machine, even though I had a master password set?

yes, this is the case and i'm not sure why this seems so wrong to you... in any case it is advised to use a unique and strong password to secure your sync account!