It'd definitely would be good to allow for expiration of master password. Even if it's buried in about:config (but setting it alongside the config for master password would be nice). GPG agent, for instance, has both a timeout (that can be extended t...