Hi all,
Put simply, not only are the logins themselves sensitive, but the corresponding web addresses are as well. When "require device sign in to fill and manage passwords" is enabled, I think the password manager should not display the websites with saved passwords/login info until a device sign in occurs, similarly to how it is required to reveal/copy hidden passwords. This change would increase the privacy and security benefits from this convenient implementation.
Ideally, every time about:logins is accessed, a challenge to enter the primary password/or log in via "require device sign in to fill and manage passwords" should be required, just as it is currently required to reveal/copy hidden passwords. An automatic timeout to this page as well would also be welcome! I feel this behavior would also be more consistent with the current behavior of the Primary Password feature, which prevents viewing any of the saved logins, or their web addresses, until the correct primary password is entered, at least when Firefox first starts.
Thank you for your consideration, Jonathan
... View more