Pretraži podršku

Izbjegni prevare podrške. Nikad te nećemo tražiti da nas nazoveš, da nam pošalješ telefonski broj ili da podijeliš osobne podatke. Prijavi sumnjive radnje pomoću opcije „Prijavi zlouporabu”.

Saznaj više

Can still access password protected sites after log off

  • 2 odgovora
  • 1 ima ovaj problem
  • 24 prikaza
  • Posljednji odgovor od TyDraniu

more options

Using FF57. If you have the tabs set to "remember tabs from prior session on startup", you can still access password-protected sites.

Scenario: you access your banking website, log in with userid and password. If you close down Firefox with the "remember tabs" set on, you will still be able to access the banking website: 1) if you log out of the banking website and close down Firefox, when you go back in to Firefox you are taken to the "logged out" screen, but you can still scroll back and Firefox will take you to the banking site still logged in; 2) if you don't log out of the banking website and you close down Firefox, when you go back into Firefox, the banking website is still logged in ... full access to the secure site.

MAJOR SECURITY FLAW!! I have stopped using FF57 until this is fixed.

Using FF57. If you have the tabs set to "remember tabs from prior session on startup", you can still access password-protected sites. Scenario: you access your banking website, log in with userid and password. If you close down Firefox with the "remember tabs" set on, you will still be able to access the banking website: 1) if you log out of the banking website and close down Firefox, when you go back in to Firefox you are taken to the "logged out" screen, but you can still scroll back and Firefox will take you to the banking site still logged in; 2) if you don't log out of the banking website and you close down Firefox, when you go back into Firefox, the banking website is still logged in ... full access to the secure site. MAJOR SECURITY FLAW!! I have stopped using FF57 until this is fixed.

Svi odgovori (2)

more options

Looks like you're right.

more options

But... such behaviour wasn't introduced in 57. You have to clear cookies on exit to prevent being logged in after restart.

https://support.mozilla.org/en-US/kb/settings-privacy-browsing-history-do-not-track#w_use-custom-settings-for-history

Izmjenjeno od TyDraniu