GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 22:31:13 JST Rich Felker Rich Felker

    Anyone know why Firefox on Alpine Linux prompts to use a system secret store if I want it to save a credit card number, and how to tell it no I don't want that I want it to do the saving itself in my profile dir like it does for secrets that are orders of magnitude more impactful?

    In conversation about 4 days ago from hachyderm.io permalink
    • Embed this notice
      yoasif (yoasif@mastodon.social)'s status on Wednesday, 14-May-2025 22:45:39 JST yoasif yoasif
      in reply to

      @dalias I believe this is just using OS authentication to validate access to this data (and not actually storing it differently). Can you share the prompt you see?

      In conversation about 4 days ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 22:45:39 JST Rich Felker Rich Felker
      in reply to
      • yoasif

      @yoasif I'll screenshot it next time it comes up. But anyway, the point is I want no "desktop integration" here, just for Firefox to operate independently and save/use the data I asked it to.

      In conversation about 4 days ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 22:47:00 JST Rich Felker Rich Felker
      in reply to
      • yoasif

      @yoasif I imagine it's another case of Mozilla asshat lawyers thinking they are party to actions you use the software to perform, and that "protecting card numbers" is something they're obligated to do for PCI compliance. 🤬

      In conversation about 4 days ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 22:49:11 JST Rich Felker Rich Felker
      in reply to
      • yoasif

      @yoasif That would affect the password manager, which is not affected. And it's documented as only being on Windows and Mac.

      In conversation about 4 days ago permalink
    • Embed this notice
      yoasif (yoasif@mastodon.social)'s status on Wednesday, 14-May-2025 22:49:12 JST yoasif yoasif
      in reply to

      @dalias FWIW, I believe this is the feature, and under the hood, it doesn't change the way the data is stored, it is more of a roadblock to people who can't exfiltrate your data: https://support.mozilla.org/en-US/kb/firefox-password-authentification-prompt

      In conversation about 4 days ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Secure Firefox passwords with device sign-in | Firefox Help
        Learn more about this Firefox anti-snooping feature designed to protect your logins and passwords from unauthorized access.
    • Embed this notice
      yoasif (yoasif@mastodon.social)'s status on Wednesday, 14-May-2025 22:50:06 JST yoasif yoasif
      in reply to

      @dalias Eh, I think it is a real feature - security comes in layers - but it isn't going to work for a determined hacker.

      In conversation about 4 days ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 22:50:06 JST Rich Felker Rich Felker
      in reply to
      • yoasif

      @yoasif If it were for security they'd be applying it to the data that's actually dangerous to lose - login credentials and session keys - not credit card numbers where it's the bank who's screwed if you lose them.

      In conversation about 4 days ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 23:24:56 JST Rich Felker Rich Felker
      in reply to
      • yoasif

      @yoasif Thanks for finding the keyword, OSKeyStore.

      Apparently this was intentional breakage as the outcome of https://bugzilla.mozilla.org/show_bug.cgi?id=1486954

      No idea if there's a configuration knob to fix it.

      In conversation about 4 days ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Invalid Bug ID
        Sorry, I can't find "1486954No". It does not seem like bug number nor an alias to a bug.
    • Embed this notice
      yoasif (yoasif@mastodon.social)'s status on Wednesday, 14-May-2025 23:24:57 JST yoasif yoasif
      in reply to

      @dalias I think that there is some integration with your "OSKeyStore":

      https://searchfox.org/mozilla-central/source/browser/extensions/formautofill/content/manageDialog.mjs#23

      Some references to this in automated tests:

      https://searchfox.org/mozilla-central/source/toolkit/modules/tests/browser/browser_CreditCard.js

      I found someone referencing this in troubleshooting as well: https://www.codejam.info/2022/05/firefox-credit-card-autofill-not-working-on-linux.html

      In conversation about 4 days ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: www.codejam.info
        Firefox credit card autofill not working on Linux
        from @valeriangalliat
        Firefox 79 introduced credit card autofill capability back in summer 2020. The feature is limited to a few regions, starting with US, and now supporting US, CA, UK, FR and DE.
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Wednesday, 14-May-2025 23:31:13 JST Rich Felker Rich Felker
      in reply to
      • yoasif

      @yoasif So it looks like for now the answer is just "Firefox storing credit cards doesn't work because they insist on it using some desktop-integration-centric secret management and they even intentionally removed the support for not doing that". 🤬

      In conversation about 4 days ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.