When Firefox asks for the Primary Password, the password field currently appears in a small pop-up dialog. I’m concerned that this could be imitated by a malicious website, making it easier for users to mistake a fake prompt for a genuine Firefox password request.
Could Firefox consider moving the Primary Password entry to a UI element that is clearly part of the browser for example, the top toolbar menu area, rather than displaying it as a pop-up?
The goal would be to make it immediately obvious that the password is being requested by Firefox itself, not by the website currently being viewed. This could provide an additional layer of protection against phishing while also making the origin of the password prompt clearer to users.
Thank you for considering this!