20 ms·
Password generator doesn't generate new password in the same session
- makepanic 4y agoMost recent issue that tracks this is https://bugzilla.mozilla.org/show_bug.cgi?id=1551723 https://bugzilla.mozilla.org/show_bug.cgi?id=1551723
- SahAssar 4y agoThis is pretty absurd and goes against every expectation I'd have of a password generator. The only reason I can think of it being useful is if the site has a separate screen for a confirm password field, but even then the password should be saved in the password manager the first time it is submitted.
- 0x6c6f6c 4y agoExcept the confirm password field is in the same form so hasn't been submitted. This very well could be the expected behavior to allow for the potential states of form entry and submission and the immense number of issues related to networking. Whether this could be changed by a preference perhaps is definitely a possible avenue here, but if they want to have it this way so people are less likely to lose their password during sign-up then so be it. Pick another password manager if you don't like it, but for the common user it's probably the best experience out of the box (even if I don't want it that way either)
- sys42590 4y agoHas anyone the time to do a code review on that: I would not be surprised if there's even less entropy in Firefox generated passwords than the bug report might indicate (e.g. just uses time and domain as random seed). If that's the case it would make a new "named" vulnerability (FOXHOLE, FIREBLEED, whatever).
- haasted 4y agoIt generates the same password when on the same domain. There's probably a usability explanation for this behaviour, rather than lack of entropy. Wish the responder would have spend some time elaborating on "why" rather than just stating that it's "by design".
- sys42590 4y agoLack of entropy when generating keys and passwords leads to things like the infamous Debian weak SSH keys vulnerability from 2008: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0166 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0166 So I'd prefer secure passwords instead of convenient passwords...
- forgotpwd16 4y agoSeems they saw the submission and edited their response, appending the following: EDIT 2022-12-20: There are at least 3 cases where this is desirable within a short period of time: 1. Filling password confirmation fields on the same page if we were not able to automatically do so. 2. Filling the same password on the next page 3. The password didn’t save on the change form so you need to fill it on the log in page. Bug 1551723 will give the user the option to choose a new password. #1551723 tracked @ https://bugzilla.mozilla.org/show_bug.cgi?id=1551723 https://bugzilla.mozilla.org/show_bug.cgi?id=1551723
- nebalee 4y agoIt only generates the same password if the browser session is also the same, i.e. it generates a different password for the same domain if the browser was closed in the meantime.
- mnoorenberghe 4y agoIt uses a PRNG with no site-specific seed, it just stores that result temporarily so it can be filled it password confirmation fields or login forms during the same session to ensure the user can complete their password change process. Code: https://searchfox.org/mozilla-central/rev/abcee8d2c97a5c8a1fbeaf84607ea427be72497a/toolkit/components/passwordmgr/PasswordGenerator.jsm#162 https://searchfox.org/mozilla-central/rev/abcee8d2c97a5c8a1f...
- sys42590 4y agothanks for the link, much appreciated
- turtleman1338 4y ago>This is currently by design What?
- chrisallenlane 4y agoI'd be incredibly interested to hear the rationale for this decision. Seems like an obviously disastrous idea.
- thatguy0900 4y agoOnly thing I can think is that sign up forms make you enter a password twice to prevent you from making a typo in the password. So with this you can right click and generate a password in both password fields and it will be the same password in both
- enedil 4y agoI would claim that this is much more common than the scenario described in the bug report.
- viraptor 4y agoLastPass, 1password and bitwarden are happily filling out both fields with the same generated password without preventing new password generation. Seems like a solved problem.
- iudqnolq 4y agoThey happily try. But there are so many poorly coded websites they can't handle all possibilities. This seems like a useful feature, although I prefer the way 1password solves it. (They handle multiple accounts on the same site, so their UI is a list rather than a single item. "Generate a random password" is just a special list item, so they can show you both.)
- Ekaros 4y agoAlso the fact that it isn't uncommon that you need to actually log in on site for browser to actually try to remember password or prompt the storage to right associated url.
- jonnycomputer 4y agoAnd here https://bugzilla.mozilla.org/show_bug.cgi?id=1786712 https://bugzilla.mozilla.org/show_bug.cgi?id=1786712 This is sort of a ridiculous bug, tbh. What rationale could this be "currently by design"?
- deleted 4y ago[deleted]
- pritambaral 4y agoI'm very thankful this is the current design. When I noticed it, I needed it to do exactly what it does, and was honestly quite pleasantly surprised it worked this way. You see, I'd just tried to create an account on a website with a slow network link. The website then failed to load. I wasn't sure if my account had been created or not. I always wait for the account creation step to succeed before I save a password, so I hadn't yet saved this random password. I was a bit worried I'd have to go through a lengthy password reset process, on my slow internet link. Fortunately for me, going back to the account creation page simply popped up the same password, so I just hit the "Sign Up" button again, without worry of losing my password again.
- jonnycomputer 4y agoI always paste into a text file until ive confirmed everything works as expected
- forgotpwd16 4y agoHaving to take such steps sounds like what you're using isn't working right. Fortunately Firefox doesn't need you to do this.
- jonnycomputer 4y ago- I didn't know this is the expected behavior of FF - I'm paranoid about getting locked out of certain accounts by stupid accidents (particularly on badly designed web sites). I temporarily copy old password too, when changing to a new one. - I do wish Firefox's password manager maintained a history of previous passwords like LastPass does.
- bakhy 4y agoThis is quite easy to reproduce. Wow. IMO they should just remove the password generator feature. It's barely usable, and with this behavior it's just dangerous. Why barely usable? Some really simple features are missing. I miss the ability to specify password requirements - for annoying sites which specify length, require so and so many these and those types of characters, or even forbid some types. And another one is that it's not possible to manually generate a password, not even in the password storage UI, when manually adding a new entry. So, if a site did not correctly declare a password field, which happens, you must generate a password yourself somehow.
- weird-eye-issue 4y ago> This is quite easy to reproduce. Wow. If you read the page you would see it is functioning by design and the bug was closed 3 years ago. Not saying that is the proper behavior, but that would explain why you can reproduce it.
- haasted 4y agoWhy do you find the feature "barely usable"?
- Ayesh 4y agoIt is a hit or miss, as some password fields don't get this. However, I personally fund it useful and use it about 100/% of the time in new signups/resets when available.
- mnoorenberghe 4y agoI believe you can right click in any type=password field to bring it up with the heuristics didn’t detect it as a new password field.
- riskable 4y agoYeah that's the problem though: A lot of websites don't set the password field to "type=password" or they don't set the second (verify) password field like that. Why do they do this? Either the web developer didn't really know what they were doing or they were given some very unique requirements (e.g. need to work with a legacy framework).
- dncornholio 4y agoCan someone explain me what the issue is with this? Not a hypothetical reason, but a real life example?
- TrianguloY 4y agoAs the comment suggests: you are an admin and you need to create a few new accounts. If you do need to create hundreds you will probably use a batch script or something, but for just a couple using a web ui seems more convenient, and using an autogenerated password helps you. In that case, if you are not paying attention all the new accounts will have the same password, which is a privacy issue.
- ekianjo 4y agonot so much a privacy issue than a security one
- TrianguloY 4y agooops, you are right. Can't edit now :(
- dncornholio 4y agoSmart! But such an edge-case, I don't find this bug as ridiculous.. On another note, admin shouldn't be sending entering other peoples passwords anymore, they should be sending invites links that let's the user insert their own.
- hackmiester 4y agoThat is a narrow view of all the different ways people might use a Web service.
- Xelynega 4y ago"The admin never knows the user's password" is a pretty simple security step for any setup. What way would someone want to use a web service where the admin knowing their password is a requirement?
- pontilanda 4y agoIs it a bug or a feature? Depending on the exact wording, I completely expect the browser to suggest the same password for the same website in the same session for the same user. Websites are crap and sometimes you need to enter the same password twice before the browser has gotten the notice to actually save the first one.
- hoseja 4y agoYes, with autogenerated passwords you want to be extra-sure the machine has actually remembered them and the process breaks down sometimes. This is a good (if unexpected, should be advertised) feature and I can't see security implications.
- zwirbl 4y agoWhen using 1Password this bit me once when I was signing up to my countries online finance and tax management. I managed to sign up and store the wrong password, without being able to look up the previously generated one. For extra "learned my lessons annoyance" I needed to get a new signup-code via snail mail to change the password.
- acdha 4y agoThat's impressive for 1Password with the history feature but I wouldn't put anything past financial systems. One of our utilities broke their bill payment system in some manner that I was able to save my new password, have it be rejected on login, and then when I followed the password reset flow and tried to use that password it was rejected because it was the same as the current password.
- ThePowerOfFuet 4y agoPassword truncated at [login|reset] but not vice versa.
- acdha 4y ago
- jmclnx 4y agoIf you are on a UN*X Type system, you can create your own random passwords very easily. tr -cd "[:alnum:]" < /dev/urandom | fold -w 20 | sed 10q So I have no need for these fancy password generators :)
- usr1106 4y agoThe are unlimited ways of writing such oneliners. Only allowing alphanumeric characters seems wrong to me and will be rejected by many sites.
- BrotherBisquick 4y agoIn that case, [:print:] instead of [:alnum:] will include all printable characters. Although I'm pretty sure I've met websites that require brackets and ampersands but will reject, say, periods and underscores, because web developers are sociopaths.
- TechBro8615 4y agoI've never had a website outright reject certain special characters, but I've had some passwords silently accepted at signup and then rejected at login. So I usually randomize the password until it doesn't include any backslashes or asterisks...
- ThunderSizzle 4y agoI've had this happen on pure length. I believe KeePass defaults to 20 characters. I've seen websites accept 20 characters on sign up, but internally, the log in only accepts 12 characters, but it doesn't truncate the input either. I had to enter the first 12 characters and submit the form, and it worked. I was completely baffled on why it was designed that way - if you're going to truncate the password, the login field should do the same.
- ipython 4y agoOmg you must have incredible luck when filling out sign in forms. There must be some sort of sadistic instinct on the types of people who design password forms. I’ve had passwords rejected for being too long (over 15 characters), including the “wrong” kind of special characters, having the same character repeated twice in a row, not having enough numbers, just to name ones I can remember off the top of my head. Oh the best ones don’t tell you the rules until after you’ve been rejected. A special place in hell is reserved for those websites that consider themselves too cool for a password manager. They actively block auto fill or cut & paste in the password field. I don’t envy the 1password devs for having to put up and work around this stuff.
- TrianguloY 4y agoCould be "fixed" by showing two entries: "previous password" and "new password". This will change the ui a bit though.
- GloriousKoji 4y agoI can't remember the last time Firefox changed an UI element that made things better... when they combined the Refresh and Stop button?
- dbttdft 4y ago