Przeszukaj pomoc

Unikaj oszustw związanych z pomocą.Nigdy nie będziemy prosić Cię o dzwonienie na numer telefonu, wysyłanie SMS-ów ani o udostępnianie danych osobowych. Zgłoś podejrzaną aktywność, korzystając z opcji „Zgłoś nadużycie”.

Więcej informacji

Can still access password protected sites after log off

  • 2 odpowiedzi
  • 1 osoba ma ten problem
  • 24 wyświetlenia
  • Ostatnia odpowiedź od TyDraniu

more options

Using FF57. If you have the tabs set to "remember tabs from prior session on startup", you can still access password-protected sites.

Scenario: you access your banking website, log in with userid and password. If you close down Firefox with the "remember tabs" set on, you will still be able to access the banking website: 1) if you log out of the banking website and close down Firefox, when you go back in to Firefox you are taken to the "logged out" screen, but you can still scroll back and Firefox will take you to the banking site still logged in; 2) if you don't log out of the banking website and you close down Firefox, when you go back into Firefox, the banking website is still logged in ... full access to the secure site.

MAJOR SECURITY FLAW!! I have stopped using FF57 until this is fixed.

Using FF57. If you have the tabs set to "remember tabs from prior session on startup", you can still access password-protected sites. Scenario: you access your banking website, log in with userid and password. If you close down Firefox with the "remember tabs" set on, you will still be able to access the banking website: 1) if you log out of the banking website and close down Firefox, when you go back in to Firefox you are taken to the "logged out" screen, but you can still scroll back and Firefox will take you to the banking site still logged in; 2) if you don't log out of the banking website and you close down Firefox, when you go back into Firefox, the banking website is still logged in ... full access to the secure site. MAJOR SECURITY FLAW!! I have stopped using FF57 until this is fixed.

Wszystkie odpowiedzi (2)

more options

Looks like you're right.

more options

But... such behaviour wasn't introduced in 57. You have to clear cookies on exit to prevent being logged in after restart.

https://support.mozilla.org/en-US/kb/settings-privacy-browsing-history-do-not-track#w_use-custom-settings-for-history

Zmodyfikowany przez TyDraniu w dniu