stored password security in firefox
I just installed Brave, and clicked on "Import settings & bookmarks", then chose Firefox from a popup list
Without typing my password, or doing anything else, Brave then instantly imported all of the saved passwords that I had stored in Firefox. I can now view all of my most secret saved passwords of Firefox... in Brave
This makes me wonder, if Brave can instantly import (and display in clear text) all of my Firefox saved passwords, couldn't any other rogue app do exactly the same?
Shouldn't they be stored in an encrypted format, at least?
Am I missing something or are the passwords wide open that Firefox saves?
Alla svar (1)
Are you using a primary/master password because if you do not use it then it is quite easy to get the logins because the encryption key is stored in key4.db (SQLite database) ?
If you use a Primary Password then you shouldn't be possible.