Friends password synced with my account
Hello,
I was at a friend last night and logged into my monzilla account on his firefox browser. To my shock all his passwords, over 300 of them, got added to my password. I just want to point out here that his passwords were stored locally without an account. As soon as I logged in it started syncing on my account. This is a HUGE SECURITY BREACH and should be addressed immediately. there should at least be a prompt or 2 making sure that I want to add locally stored password to my account or not.
If I had not noticed it at that time I would probably have gotten away with all of his passwords without me or him knowing. I had to manually delete the ~300 entries. makes you think how many times this already happened in the past for others.
Best regards, Remco
Solution choisie
Yes I did this immediately, my problem is solved now
Lire cette réponse dans son contexte 👍 1Toutes les réponses (7)
Hi
Firefox Sync is designed to do just that - sync passwords, bookmarks and other data between copies of Firefox.
You may also want to check to see if your passwords and bookmarks are now on your friends device.
You would think there would be at least a prompt to ask me if I want to sync local stored passwords (not linked to any account) that are not even mine right? I did not even click on sync. it's just so weird to me that that can happen. so If you would login to my browser for example you'd have my passwords and I have yours. where is the logic in that?
This might refrain me from using the browser as a whole which would be a shame because I like it allot.
As said it's sync regardless of Firefox computers running the browser. Now you have to change your login and hopefully your friend doesn't get excited to see what's in your closet. Let this be a learning lesson never login in on a computer not yours or has separate password protected accounts.
My apologies, i taught that it synced to the cloud and then back to my devices. This was not explicitly told when I activated it. It only syncs from a device to another without the cloud.
My bad for the misunderstanding.
Did you disconnect Sync on your friends computer as in that case Firefox might have asked whether to remove synced data ?
Solution choisie
Yes I did this immediately, my problem is solved now
Note that Firefox doesn't sync directly to other devices, it uploads data from all connected devices to the Sync server and merges that to the other connected devices.