LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-06-2006, 06:05 AM   #1
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794
Blog Entries: 2

Rep: Reputation: 30
Firefox storing root password


This may be a minor point, but I was browsing through the firefox stored passwords, and noticed that it had my root password in there. This happened when I installed my printer via CUPS. It must have offered to remember the password and I clicked yes as usual. It's probably not a good idea to have roots password stored on your hard drive, even encrypted in firefox. I just thought I'd point this out.
 
Old 03-06-2006, 06:23 AM   #2
spooon
Senior Member
 
Registered: Aug 2005
Posts: 1,755

Rep: Reputation: 51
Quote:
Originally Posted by simcox1
It's probably not a good idea to have roots password stored on your hard drive, even encrypted in firefox.
It's not a good idea to have passwords stored at all. They can't "encrypt" your password because they still need to store the key to "decrypt" it somewhere, which defeats the point.
 
Old 03-06-2006, 06:34 AM   #3
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794

Original Poster
Blog Entries: 2

Rep: Reputation: 30
So your saying stored passwords in firefox are a security risk? Things like paypal and email passwords? I use firefox password manager a lot.
 
Old 03-06-2006, 07:02 AM   #4
scuzzman
Senior Member
 
Registered: May 2004
Location: Hilliard, Ohio, USA
Distribution: Slackware, Kubuntu
Posts: 1,851

Rep: Reputation: 47
If someone gets access to your box, and your user account, they have your passwords.
 
Old 03-06-2006, 07:40 AM   #5
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Maybe use the "master password" feature?
 
Old 03-06-2006, 08:25 AM   #6
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794

Original Poster
Blog Entries: 2

Rep: Reputation: 30
That's probably a good idea to use the master password. I've got a lot of info in firefox. It is a bit of a security loophole though. Stored passwords are a godsend. The reason I was looking through them is because i got caught up in an ebay scam. Someone was selling a hifi for a great price, saying to email them personally to buy it now. I emailed them and then ebay removed it saying someone's account had been compromised and it was a scam. Now this person has my email address. I didn't send any money, but I've changed my registered email address and passwords.
 
Old 03-07-2006, 09:41 AM   #7
dracolich
Senior Member
 
Registered: Jul 2005
Distribution: Slackware
Posts: 1,274

Rep: Reputation: 63
Personally, I would have Firefox (or any other browser) never remember passwords. It's not that hard to type it every time, just a few extra keystrokes.
Go to Preferences -> Passwords and make sure the Remeber Passwords box is unchecked, then clear all saved passwords, then whenever it offers to remember a password cleck Never For This Site.
And always "log out" or "sign out" when finished to erase cookies that might have ID/password combinations in them.
 
Old 03-07-2006, 10:04 AM   #8
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Quote:
Originally Posted by scuzzman
If someone gets access to your box, and your user account, they have your passwords.
What kind of encryption/hashing is used in Firefox? That would suprise me if you can decode an encrypted password.

I'm not sure I see a security problem in storing passwords in firefox but I may be wrong.
Any scenario?
Maybe with XSS (CrossSiteScripting) but I'm not even sure.

I store all my password in Firefox coz I'm lazy
 
Old 03-07-2006, 10:08 AM   #9
simcox1
Member
 
Registered: Mar 2005
Location: UK
Distribution: Slackware
Posts: 794

Original Poster
Blog Entries: 2

Rep: Reputation: 30
Well like he says, if someone gets access to your user account, they can get the passwords. As user I can view them in firefox. I'm not even sure they're encrypted. All I can do is set a master password or not use them at all.
 
Old 03-07-2006, 10:12 AM   #10
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
Ah yes you're right, I've missed the point
Sure I use master password. But I'm still wondering if by XSS even with master password it is not possible to get your password.. as they stay in memory for a while
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How could normal user obtain root password or change root password ckamheng Debian 18 02-18-2009 10:28 PM
How to retrieve( or reset) root password in Mandrake Linux, as I forgot my password? Reghunath Linux - Software 4 05-08-2008 04:11 AM
Booting into Single User on MDK 9 asks for root password instead of booting into root acadcworks Linux - General 6 01-10-2006 06:51 AM
Password storing program? Ariod Linux - Software 2 09-09-2005 06:25 PM
Logged in as root, prompted for root password ta0kira Slackware 13 04-25-2005 01:29 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:11 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration