4 ms·
> This barcode was stored on my hard drive unencrypted as a simple image You mean like the HTTP cache? Maybe I'm reading this bug wrong, but it appears to be
by nephyrin 14y ago
> This barcode was stored on my hard drive unencrypted as a simple image
You mean like the HTTP cache?
Maybe I'm reading this bug wrong, but it appears to be a verified bug with csec-disclosure and sec-low security ratings. Not finding this to be as critical as you is hardly "saying its okay" (it's not)
- laurencei 14y agoYes - except this is HTTPS cache - and takes screenshots of your HTTPS data. Its silly because they turned off viewing the HTTPS websites on the 'newtabs' and replaced it with grey screens - yet they still take the screenshot. The sec-low status was given because they mention the low res screenshots are not enough to get anything useful - but I've just proven that not true. Besides - how many people do you think would know/expect their HTTPS screenshots to be captured and stored on the drive? Accessed a bank site lately, visited a secure Government website etc etc
- nephyrin 14y ago> Yes - except this is HTTPS cache - and takes screenshots of your HTTPS data. HTTPS is also cached by every major browser, meaning the image in question would be in your cache just as well as the screenshot containing it. > Its silly because they turned off viewing the HTTPS websites on the 'newtabs' and replaced it with grey screens - yet they still take the screenshot. If this is true you should file a bug for it. Bug 754608 / Bug 627239 / Bug 822867 suggests that this is not the case, and that capturing them was disabled entirely. In fact, those three bugs suggest that this bug is only open because a better replacement for grey-squares is needed? > The sec-low status was given because they mention the low res screenshots are not enough to get anything useful - but I've just proven that not true. This does not seem to match what I see on the thread. The bug was filed by a mozilla developer and the consensus seems to be that it is definitely an issue: c0 - Mozillian files the bug c4 - Mozillian mentioning they think screenshots of any size could be sensitive -- the opposite of "not enough to get anything useful" -- but also that it's not something that can be reasonably fixed. c5 - Mozillian acknowledging its a problem and suggesting its difficult to properly fix c8 - Mozillian noting this is an even bigger issue on OS X c9 - Mozillian noting that the whole concept might need rethinking c11 - Mozilla security manager assigns security classification to bug
- laurencei 14y ago> If this is true you should file a bug for it I did bug report exactly this issue - and they closed it: https://bugzilla.mozilla.org/show_bug.cgi?id=838646 https://bugzilla.mozilla.org/show_bug.cgi?id=838646
- nephyrin 14y agoThey marked it as a duplicate of the given bug, and a mozilla security manager politely explained why: > The "documentation"(?) was maybe an announcement about the changes in bug 754608, which made the thumbnails follow the caching rules for https. Https pages can indeed be cached depending on whether or not they're marked "no-store". bug 755996 (and you, in this bug) says that's not good enough which may be true, but is already covered in bug 755996. ... Which seems to be a fair explanation of the situation. HTTPS pages that are cached can still cache their thumbnails. I'm still not seeing the outrage-worthy malfeasance here.