4 ms·
Disclaimer: I'm the Firefox sec engineer working on this feature. Just to clear this up: The code for this is actually way simpler and sends no data to either
by groovecoder 7y ago
Disclaimer: I'm the Firefox sec engineer working on this feature.
Just to clear this up: The code for this is actually way simpler and sends no data to either Mozilla nor HIBP. To prevent Firefox from sending data update pings to HIBP, Firefox Monitor maintains a copy of publicly available HIBP breaches and their metadata [1] in the Firefox "Remote Settings" service. [2]
Using that data, Firefox simply checks for saved logins for breached sites where the saved password is older than the breach. [3]
[1] https://haveibeenpwned.com/api/v2/breaches https://haveibeenpwned.com/api/v2/breaches
[2] https://wiki.mozilla.org/Firefox/RemoteSettings https://wiki.mozilla.org/Firefox/RemoteSettings
[3] https://hg.mozilla.org/mozilla-central/file/6484c07ff83649914781ddc9cfb70e98466cdd7a/browser/components/aboutlogins/AboutLoginsParent.jsm#l377 https://hg.mozilla.org/mozilla-central/file/6484c07ff8364991...
- MrStonedOne 7y agoThis explanation confused me, so let me rewrite it: "Firefox downloads a list of breached domain names and the date they were breached, and merely checks if you have any stored logins on any breached domains that are older then the breach date."