Security/Features/HighlightCleartextPasswords: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
No edit summary
Line 81: Line 81:


This feature does not prevent against active attacks (ex: man-in-the-middle on http pages).
This feature does not prevent against active attacks (ex: man-in-the-middle on http pages).
|Feature functional spec=Phase 1: Use cases 1-3 - General case.
|Feature functional spec=Phase 1: Do not autopopulate the username/password stored in password manager for http sites.  Provide the multiuser experience seen [https://people.mozilla.com/~tvyas/multiuser_experience.jpg here].


Phase 2: Use case 4 & 5 - Deal with mixed content.  Blocked on bug 62178.
Phase 2: Use cases 1-3 - General case.
 
Phase 3: Use case 4 & 5 - Deal with mixed content.  Blocked on bug 62178.
|Feature ux design=Multiple options here.  See Open Issues - "What do we mean by Highlight."
|Feature ux design=Multiple options here.  See Open Issues - "What do we mean by Highlight."
|Feature implementation plan=https://bugzilla.mozilla.org/show_bug.cgi?id=748193
|Feature implementation plan=https://bugzilla.mozilla.org/show_bug.cgi?id=748193
Line 89: Line 91:
Phase 0: User Research.  First on the password field itself, then later on how to redirect to the secure version of the site.  
Phase 0: User Research.  First on the password field itself, then later on how to redirect to the secure version of the site.  


Phase 1: Use cases 1-3 - General case.
Phase 1: Do not autopopulate the username/password stored in password manager for http sites.  Provide the multiuser experience seen [https://people.mozilla.com/~tvyas/multiuser_experience.jpg here].
 
Phase 2: Use cases 1-3 - General case.


Phase 2: Use case 4 & 5 - Deal with mixed content.
Phase 3: Use case 4 & 5 - Deal with mixed content.
}}
}}
{{FeatureInfo
{{FeatureInfo
canmove, Confirmed users
285

edits

Navigation menu