Showing results for 
Show  only  | Search instead for 
Did you mean: 

extreme security flaw with autofill from firefox

Making moves

the autofiller from firefox fills in the password "enter current password" in the android and desktop version when you want (or someone else wants to change respectively see) to change the password for firefox sync (in settings sync).

the password access per fingerprint makes no sense this way. It should not autofill the password for the access to all passwords to be autofilled from the firefox browser.

Also the masterpassword feature makes no sense this way (besides that you can just cancel or check the cross to use all the prefilled passwords of shopping and so one websites).

maybe only few people would always delete the firefox sync password in the pw manager from firefox again and again to prevent this security flaw.