cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Liups233
New member
Status: New idea

I found that many people’s Google accounts have been hacked because malware can read the plain text cookie database file. Why cannot it be encrypted with the master password?

I have set up a master password.  I have to enter it every time I open the browser, and the password will be decrypted. I think cookie file can do the same thing. 

2 Comments
Status changed to: New idea
Jon
Community Manager
Community Manager

Thanks for submitting an idea to the Mozilla Connect community! Your idea is now open to votes (aka kudos) and comments.

TechHorse
Familiar face

While I can appreciate the security aspect of encrypting the cookies, there are a couple of issues here.

 

First, please make any cookie-encryption optional.

 

Second, for those who want to enable this, please offer the option of creating a new independent cookie unlock password, instead of having to use the existing primary password for both cookies and logins.

 

The first request is for those who do not currently have to enter a password for each Firefox session, and who do not wish to start having to in order to unlock mandatorily-locked cookies.

 

The second request is for those who only need to enter their primary password to access their stored logins once every several sessions, and / or who like to immediately relock them after they have signed in to a site. Whereas cookies would of course need to be unlocked more or less for the entire time that Firefox is running.

 

Clearly for such users, not having independent cookie / login unlocks would be less secure, as they would now need to enter their primary password to unlock cookies for each and every session, and their logins would also now be unlocked for the entire time that Firefox is running.