Security Issue: Using GM_setValue to store passwords
![]() ![]() |
Hey, Nice script Jarett! I am concerned with having my passwords available in about:config in clear text however, and I don't think it is necessary. I wrote a similar userscript for Twitter at http://userscripts.org/scripts/show/59103 which you can review for my implementation without storing passwords. To briefly explain my userscript:
Do you think that you could do something similar for this script? |
![]() ![]() |
You can leave the password blank if you want; it will prompt you for it when you switch accounts. Choosing to store passwords via my script is no less secure that having Firefox remember the site password without a master Firefox password. Also, I would appreciate it if you didn't title the post "Security Issue"; I really don't want an angry mob of thousands of panicky users banging down my door. |
![]() ![]() |
Choosing to store passwords via my script is no less secure that having Firefox remember the site password without a master Firefox password. Exactly, the master password makes user passwords secure. Also, I would appreciate it if you didn't title the post "Security Issue"; I really don't want an angry mob of thousands of panicky users banging down my door. I doubt you will get mobs, if anyone (like it matters) and people should know the risk. |
![]() ![]() |
Erik, you do bring up a fairly valid point. However, I'm not going to bother changing it for two reasons:
|
![]() ![]() |
Fair enough Jarett, no worries. |
![]() ![]() |
Thanks for understanding. Feel free to make your own edited version and put it up; I don't mind as long as you link back to the original script. |



