
You’ve most likely have seen and checked the box for “Save My Password”, “Remember My Login Credentials”, or something similar. Many of us still do it because hey, why not save ourselves a few keystrokes? Fact is these saved logins could be compromised during data breaches and we would never know until a public article is released or you receive an email notification that looks just like a phishing scam, but is actually legit and you end up not changing your password anyway. Wouldn’t it be great if our browsers, apps, or services notified us of compromised credentials as soon as it hits the dark web or earlier than a public article or email notification?
Firefox Lockwise does just that in it’s latest release, Firefox 70. Their independent service Firefox Monitor service will scan saved login credentials stored in Firefox Lockwise password manager and warns users of exposed credentials in data breaches listed through their partnership Have I Been Pwned. The downside is that the feature only works for credentials saved prior to being exposed in data breaches. Firefox users will be notified of exposed credentials via an alert in Firefox Lockwise that reads “Passwords were leaked or stolen…”
This is a great feature and all browsers, apps, or services that allow the saving of credentials should have some accountability in the services that they provide. Let’s say you are a trusted entity for example. If I write down my password on a piece of paper and entrust it to you to hold onto, I trust that you will keep it safe by taking the proper measures to protect it from prying eyes, being stolen, or shared with those whom I did not authorize to see. If somehow my password was exposed, yes shame on me for entrusting it to you, but like we entrust our money to our banks, you were made accountable for keeping that password safe and I should be notified in a timely manner if it was exposed in any way. In this case, the trusted entities are the numerous websites and businesses that store our credentials, Firefox is just a password keeper that takes the accountability of the trusted entities into their own hands by providing a great service to their valued users.
Accountability must be taken by any person, business, or service when it comes to holding something of value and keeping it safe. Recall my last post where I phrased “Convenience is the enemy and users are the weakest link.” Convenience doesn’t have to be the enemy, but how it is practiced and utilized today, it is. If we can somehow make convenience our friend and take accountability, users can become stronger links. Mozilla Firefox has the right idea. Create a password manager that people will use conveniently because it will make them better users by notifying and enforcing them to reset their passwords when their credentials have been exposed.
Source:
Bleeping Computer – Firefox to warn when saved logins are found in data breaches










