cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Damariobros
Strollin' around
Status: New idea

Currently, when you try to access accounts through Mozilla Account SSO in a signed-in browser, no re-authentication of any kind is required to proceed. This means that with mere access to the browser, one has full access to any account which uses Mozilla Account SSO, including websites such as this very Ideas Forum, or perhaps more sensitive accounts such as Mozilla Monitor. Not your account password or your 2FA or even your Primary Password is required.

There should be an option, whether in your Mozilla Account settings or in the Primary Password settings, to require some kind of Re-Authentication when going through an SSO flow using your Mozilla Account, even if you are already signed-in to a Mozilla Account, and even if you are in a signed-in and synced Firefox browser.

1 Comment
Status changed to: New idea
Jon
Community Manager
Community Manager

Thanks for submitting an idea to the Mozilla Connect community! Your idea is now open to votes (aka kudos) and comments.