본 사이트는 여러분의 사용자 경험을 개선하기 위해 유지 보수를 진행하는 동안 기능이 제한됩니다. 도움말로 문제가 해결되지 않고 질문을 하고 싶다면 Twitter의 @FirefoxSupport 및 Reddit의 /r/firefox 채널을 활용하세요.

Mozilla 도움말 검색

고객 지원 사기를 피하세요. 저희는 여러분께 절대로 전화를 걸거나 문자를 보내거나 개인 정보를 공유하도록 요청하지 않습니다. "악용 사례 신고"옵션을 사용하여 의심스러운 활동을 신고해 주세요.

자세히 살펴보기

Role of Master Password vs Sync account password

  • 3 답장
  • 3 이 문제를 만남
  • 7 보기
  • 최종 답변자: John99

more options

I went through documentation on GitHub for Sync Protocol as well as other similar questions. I got basic understanding of how Sync security works. But still I would like experts to confirm this.

1. Master password is only used to encrypt data on local computer. 2. Sync account password is used for encrypting data before sending it to Mozilla servers. 3. Data on Mozilla servers is meaning less unless you know the Sync account password. 4. Mozilla does not store Sync account password anywhere. But instead they use hash/digest comparison method(or a similar method) to make sure that entered password is correct.

Could anyone please confirm above points?

One additional related question I have is, 1. Even if I do not set master password, I see that data is logins.json is encrypted. How this encryption is achieved?

I went through documentation on GitHub for Sync Protocol as well as other similar questions. I got basic understanding of how Sync security works. But still I would like experts to confirm this. 1. Master password is only used to encrypt data on local computer. 2. Sync account password is used for encrypting data before sending it to Mozilla servers. 3. Data on Mozilla servers is meaning less unless you know the Sync account password. 4. Mozilla does not store Sync account password anywhere. But instead they use hash/digest comparison method(or a similar method) to make sure that entered password is correct. Could anyone please confirm above points? One additional related question I have is, 1. Even if I do not set master password, I see that data is logins.json is encrypted. How this encryption is achieved?

글쓴이 raghu.sodha 수정일시

선택된 해결법

Hi

Thank you for your questions. As far as I am aware, all of the statements you make are true. In respect of your additional question, I recommend you have a read of this article.

I hope this helps, but if not, please come back here and we can look into this further for you.

문맥에 따라 이 답변을 읽어주세요 👍 2

모든 댓글 (3)

more options

선택된 해결법

Hi

Thank you for your questions. As far as I am aware, all of the statements you make are true. In respect of your additional question, I recommend you have a read of this article.

I hope this helps, but if not, please come back here and we can look into this further for you.

more options

Thanks Seburo.

I went through article. It does not mention how logins.json data is encrypted when master password is not set. But anyway, it is appropriate/wise to assume that when master password is not set all your passwords are in plain text.

Thanks Seburo and Mozilla.

more options

The point is if a master password is not set anyone with access to your Firefox may obtain the logins as simply as you can. Plus anyone with access to the computer and Firefox profile also has all those logins available.

I suspect the encryption of the logins within Firefox even when a Master Password is in use not very secure but unfortunately I do not recall where I saw that mentioned. (Probably in relation to Sync & Master password bugs) If you wish to obtain further information try the Mozilla forums, and if you do post there maybe let us have the link so we may follow the post