搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

Learn More

How does Lockwise work at the secure & encrypted level?

more options

I am interested in Firefox Lockwise because I believe in Mozilla's overall philosophy to a free and privacy respecting internet.

However, the help pages are sparse on just how Mozilla and the Firefox team protects my data in transit and at rest. I want to know how secure my password data will be e.g., salted hashes, anonymizing my data and identities. It would be great to have redundancy just in case my primary password manager's company goes bankrupt or some other disaster happens which knocks out my service provider. They are very clear on how secure my data is and what steps are being taken to ensure said claims. I can make assumptions on the types of encryption both at rest and in transit, but to assume makes an ass out of "u" and me.

Also, what happens when an overreaching L/E entity or nation state requests a Lockwise user's data? What is handed over. Yes, I have checked the privacy policies that Mozilla has put out, but this question ties back to my first question. Are the logins and passwords recoverable by outside sources? Does Mozilla have access to the encryption key or build a back door into Lockwise? Again, none of this is addressed in the documentation. I get it, it's written by volunteers, but we are requesting better and greater transparency.

Lastly, I would be curious to know where the single points of failure lay within the Lockwise system and what steps Mozilla and the Lockwise dev team are taking to address these issues. And while we are at it, a project roadmap would be great. For instance, will Lockwise support encrypted note taking capability?

I am interested in Firefox Lockwise because I believe in Mozilla's overall philosophy to a free and privacy respecting internet. However, the help pages are sparse on just how Mozilla and the Firefox team protects my data in transit and at rest. I want to know how secure my password data will be e.g., salted hashes, anonymizing my data and identities. It would be great to have redundancy just in case my primary password manager's company goes bankrupt or some other disaster happens which knocks out my service provider. They are very clear on how secure my data is and what steps are being taken to ensure said claims. I can make assumptions on the types of encryption both at rest and in transit, but to assume makes an ass out of "u" and me. Also, what happens when an overreaching L/E entity or nation state requests a Lockwise user's data? What is handed over. Yes, I have checked the privacy policies that Mozilla has put out, but this question ties back to my first question. Are the logins and passwords recoverable by outside sources? Does Mozilla have access to the encryption key or build a back door into Lockwise? Again, none of this is addressed in the documentation. I get it, it's written by volunteers, but we are requesting better and greater transparency. Lastly, I would be curious to know where the single points of failure lay within the Lockwise system and what steps Mozilla and the Lockwise dev team are taking to address these issues. And while we are at it, a project roadmap would be great. For instance, will Lockwise support encrypted note taking capability?

所有回覆 (1)

more options

Hi JiGGa!, in your desktop version of Firefox (Mac, Windows, Linux), Lockwise is the name for the current UI. Your logins are stored locally on disk in your profile folder and in order to secure them from someone with physical access, or remote access, you need to create a Master Password. More info on that in this article: Use a Primary Password to protect stored logins and passwords. The Master Password is purely local and does not Sync.

Data shared between Firefox installations and between Firefox and the Lockwise app is encrypted in flight and at rest on Mozilla's servers using your Firefox Account login. By design, Mozilla cannot decrypt that data. There are other threads/articles about that in discussions of Sync, unrelated to Lockwise.