Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SECURITY] Master Password does not work until browser restart #321

Open
shinenelson opened this issue Mar 24, 2020 · 0 comments
Open

[SECURITY] Master Password does not work until browser restart #321

shinenelson opened this issue Mar 24, 2020 · 0 comments

Comments

@shinenelson
Copy link

shinenelson commented Mar 24, 2020

Steps to reproduce

  1. Install the Extension
  2. Login to Passman vault
  3. Set a Master Password ( do NOT remember it locally; what's the point of a password manager if the master key is stored unencrypted on the local file system? )
    -> Do NOT restart the browser
  4. Click the lock icon to lock the extension
  5. Click 'Unlock' button
  6. Search for saved password from vault

Expected behaviour

The extension should report an error ( #320 ) and not unlock the vault.

Actual behaviour

Due to #320 and probably because the password vault was just unsealed during setup, it is still accessible. And unlike in #320, the extension is active and triggered on website form fields. However, they don't autofill into the form fields, unlike when in properly unsealed mode, the fields are automatically filled in. All passwords is directly accessible and viewable ( at least ) from the extension though.

Screenshots

Search in locked state
Screenshot from 2020-03-24 05-09-42

Triggering on websites
Screenshot_2020-03-24 Client Area

Configuration

Operating system: Ubuntu 18.04.4 LTS

Browser: Firefox 75.0

Extensions that might cause interference: Nextcloud Passwords, LessPass

Passman version: 2.3.5

Extension version: 2.1.1

Nextcloud version: 18.0.0


Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant