<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Followup: Password Manager changes (coming in FF3 Alpha 5)</title>
	<atom:link href="http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/</link>
	<description>The odd parity bit</description>
	<lastBuildDate>Mon, 02 Jan 2012 13:15:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: DazzleCat</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-35868</link>
		<dc:creator>DazzleCat</dc:creator>
		<pubDate>Mon, 12 May 2008 11:06:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-35868</guid>
		<description>thats brilliant good stuff</description>
		<content:encoded><![CDATA[<p>thats brilliant good stuff</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sebastian Tschan</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14803</link>
		<dc:creator>Sebastian Tschan</dc:creator>
		<pubDate>Tue, 03 Jul 2007 09:17:08 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14803</guid>
		<description>With the old password manager (nsIPasswordManager) the Master Password had only been required if the username or password had to be accessed. This way you could collect existing password objects and display the number of login possibilities to the user without requiring the Master Password.
This is very useful for the Secure Login extenions, e.g.:
https://addons.mozilla.org/de/firefox/addon/4429

With the new login manager (nsILoginManager), you have to enter the Master Password as soon as the findLogins method is called.
I think it&#039;s a security enhancements not to ask for the Master Password until the login credentials are filled in.
This would also affect the standard password autofill of Firefox Password Manager, e.g. for more than one saved user+pass combination.</description>
		<content:encoded><![CDATA[<p>With the old password manager (nsIPasswordManager) the Master Password had only been required if the username or password had to be accessed. This way you could collect existing password objects and display the number of login possibilities to the user without requiring the Master Password.<br />
This is very useful for the Secure Login extenions, e.g.:<br />
<a href="https://addons.mozilla.org/de/firefox/addon/4429" rel="nofollow">https://addons.mozilla.org/de/firefox/addon/4429</a></p>
<p>With the new login manager (nsILoginManager), you have to enter the Master Password as soon as the findLogins method is called.<br />
I think it&#8217;s a security enhancements not to ask for the Master Password until the login credentials are filled in.<br />
This would also affect the standard password autofill of Firefox Password Manager, e.g. for more than one saved user+pass combination.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14357</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Sun, 17 Jun 2007 21:55:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14357</guid>
		<description>It Fly&#039;s on a 8 core Mac Pro only 2gigs of ram!</description>
		<content:encoded><![CDATA[<p>It Fly&#8217;s on a 8 core Mac Pro only 2gigs of ram!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14295</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Thu, 14 Jun 2007 22:47:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14295</guid>
		<description>I&#039;m having the same problem as replies 6 and 8. Seems to require password for the first site you visit regardless of need. 

Kind of freaked me out for a while, trojan was the first thing on my mind. Being an alpha not intended for general use and the fact I&#039;m too paranoid for my own good mitigates the issue though. Good to have it confirmed as a bug and I hope it has no impact on actual security.</description>
		<content:encoded><![CDATA[<p>I&#8217;m having the same problem as replies 6 and 8. Seems to require password for the first site you visit regardless of need. </p>
<p>Kind of freaked me out for a while, trojan was the first thing on my mind. Being an alpha not intended for general use and the fact I&#8217;m too paranoid for my own good mitigates the issue though. Good to have it confirmed as a bug and I hope it has no impact on actual security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Eric Shepherd</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14275</link>
		<dc:creator>Eric Shepherd</dc:creator>
		<pubDate>Wed, 13 Jun 2007 22:55:40 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14275</guid>
		<description>I&#039;ve finished taking the already good documentation for nsILoginManager and nsILoginInfo and turning them into our standard format for interface docs.  I still need to give the example a once-over to clean up some style stuff there, but I&#039;d appreciate any comments or tweaks to the interface docs:

http://developer.mozilla.org/en/docs/nsILoginInfo

http://developer.mozilla.org/en/docs/Using_nsILoginManager</description>
		<content:encoded><![CDATA[<p>I&#8217;ve finished taking the already good documentation for nsILoginManager and nsILoginInfo and turning them into our standard format for interface docs.  I still need to give the example a once-over to clean up some style stuff there, but I&#8217;d appreciate any comments or tweaks to the interface docs:</p>
<p><a href="http://developer.mozilla.org/en/docs/nsILoginInfo" rel="nofollow">http://developer.mozilla.org/en/docs/nsILoginInfo</a></p>
<p><a href="http://developer.mozilla.org/en/docs/Using_nsILoginManager" rel="nofollow">http://developer.mozilla.org/en/docs/Using_nsILoginManager</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ulrich</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14222</link>
		<dc:creator>Ulrich</dc:creator>
		<pubDate>Tue, 12 Jun 2007 06:52:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14222</guid>
		<description>(About http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14118)

While C++ doesn&#039;t make passwords safe automatically, a language like JavaScript that does garbage collecting, may leave passwords somewhere in memory even after they are &quot;safely&quot; stored elsewhere. Security-aware code like that in PGP takes great care to destroy the passwords in RAM once they are no longer needed.</description>
		<content:encoded><![CDATA[<p>(About <a href="http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14118" rel="nofollow">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14118</a>)</p>
<p>While C++ doesn&#8217;t make passwords safe automatically, a language like JavaScript that does garbage collecting, may leave passwords somewhere in memory even after they are &#8220;safely&#8221; stored elsewhere. Security-aware code like that in PGP takes great care to destroy the passwords in RAM once they are no longer needed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Dolske</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14206</link>
		<dc:creator>Justin Dolske</dc:creator>
		<pubDate>Mon, 11 Jun 2007 18:10:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14206</guid>
		<description>Andy:

The JS portions mostly handle DOM interaction and file IO for signons2.txt. The two main reasons for switching to JS are simpler code and increased security (eg, no buffer overflows possible). Most of the Firefox frontend is already JS, so this isn&#039;t exactly a radical change. But, in any case, the actual encryption of logins continues to be done be a C++ component (using Triple-DES).

Jack:

Yes, that&#039;s a known bug in Alpha 5. I&#039;m fixing a number of issues involving the usability of master passwords for A6.</description>
		<content:encoded><![CDATA[<p>Andy:</p>
<p>The JS portions mostly handle DOM interaction and file IO for signons2.txt. The two main reasons for switching to JS are simpler code and increased security (eg, no buffer overflows possible). Most of the Firefox frontend is already JS, so this isn&#8217;t exactly a radical change. But, in any case, the actual encryption of logins continues to be done be a C++ component (using Triple-DES).</p>
<p>Jack:</p>
<p>Yes, that&#8217;s a known bug in Alpha 5. I&#8217;m fixing a number of issues involving the usability of master passwords for A6.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bhanu Pratap</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14197</link>
		<dc:creator>Bhanu Pratap</dc:creator>
		<pubDate>Mon, 11 Jun 2007 07:58:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14197</guid>
		<description>This is great.</description>
		<content:encoded><![CDATA[<p>This is great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brajesh</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14119</link>
		<dc:creator>Brajesh</dc:creator>
		<pubDate>Sat, 09 Jun 2007 09:09:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14119</guid>
		<description>(Almost) same prob as Jack. Everytime I restart FF3a5, it asks me to enter master password, while none of my homepages require an auto-fill. It doesn&#039;t let me get through without entering the right password.</description>
		<content:encoded><![CDATA[<p>(Almost) same prob as Jack. Everytime I restart FF3a5, it asks me to enter master password, while none of my homepages require an auto-fill. It doesn&#8217;t let me get through without entering the right password.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/comment-page-1/#comment-14118</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Sat, 09 Jun 2007 08:46:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/dolske/2007/05/28/followup-password-manager-changes-coming-in-ff3-alpha-5/#comment-14118</guid>
		<description>@Andy,

the fact that the manager is written in JavaScript does nothing to weaken the security. Passwords are stored somewhere, it&#039;s _how_ they are stored that should make it safe. If you store them unaltered in a text file on the desktop, even if you use C++ to do it, it&#039;s not secure.</description>
		<content:encoded><![CDATA[<p>@Andy,</p>
<p>the fact that the manager is written in JavaScript does nothing to weaken the security. Passwords are stored somewhere, it&#8217;s _how_ they are stored that should make it safe. If you store them unaltered in a text file on the desktop, even if you use C++ to do it, it&#8217;s not secure.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

