How secure is Firefox Sync on Android

First, let me summarize how I understand the current security concept of Firefox4Linux, as some of the documents I read may be old:
L1) During sync setup Firefox4Linux creates recovery key, encrypt all passwords, bookmarks, ... using this recovery key and upload them to the server[1].
L2) Passwords are encrypted only by using the recovery key, (not by master password)[2].
L3) When pairing J-PAKE (Password Authenticated Key Exchange by Juggling) is used to securely transfer the recovery key[3].
L4) On Firefox4Linux master password is used to encrypt the Recovery Key. Based on my own observation as it is not possible to view Recovery Key without entering the master password at least once.
This all seems to me reasonably secure and there should be no leakage of recovery key without compromising Master password. Now regarding my findings for Firefox4Android:
A1) Firefox4Android stops syncing passwords when master password is used[4].
A2) Based on my observations Firefox4Android continue to sync bookmarks, tabs, ... even when it is still asking for master password and I am not providing it.
A3) Based on A1 and A2 it looks like that, recovery key is not encrypted using master password.
A4) Based on A3 anybody who gets physical access to the Android device, can get recovery key, setup synchronization on PC and obtain all the passwords!
Please let me know, if I missed something. As it looks to me, using synchronization on Firefox4Android is not secure even if you use Master Password.
Currently I see possible workaround for this issue:
1) Disable master password on Firefox4Android
2) Setup synchronization
3) Let passwords, bookmarks, synchronize
4) Disable synchronization (deleting synchronization account should delete recovery key)
5) Enable master password
Only security issue with this workaround may be, that recovery key may be readable from the NAND flash for a while, because of the wear-leveling techniques. Possible workaround for this, would be generating new recovery key, after performing each synchronization with Android.
[1] http://support.mozilla.org/en-US/kb/firefox-sync-data-secure-find-out-more
[2] https://bugzilla.mozilla.org/show_bug.cgi?id=540975
[3] http://gregoryszorc.com/blog/2012/04/08/comparing-the-security-and-privacy-of-browser-syncing/
[4] http://support.mozilla.org/en-US/kb/use-master-password-protect-passwords-firefox-andr

I would need a help, how to use Firefox Sync safely on Android devices, without that crazy workaround. I believe I am not the only person having this problem and somebody has find out something more straight forward.

Similar Messages

  • How often does Firefox Sync back-up data? I see there is no preference selection allowing you to change the pre-set frequency (whatever that interval may be).

    How often does Firefox Sync back-up data? I see there is no preference selection allowing you to change the pre-set frequency (whatever that interval may be).

    However, the sync action only triggers every 60-minute and there is no user-configurable option provided. Although one can put a Sync icon onto the toolbar for easier access, it is still far from practical needs.
    To unlock this limitation, do the following:
    1) Type “about:config” at the address bar
    2) Search for “services.sync.syncInterval”
    3) Change the value from 3600000 (milliseconds = 3600 seconds = 60 minutes) to any value (in millisecond) of your choice
    4) Close and restart Firefox
    The Sync action will now trigger at the interval you just set.
    from: http://tomtsui.wordpress.com/2011/04/29/modify-firefox-sync-interval/

  • Where is documentation on How to Use Firefox sync?

    I can find info on how to setup Firefox Sync. I can find NO INFORMATION on how to use it.

    Hello,
    First, you are using an outdated and insecure version of Firefox. It is highly recommended that you update it:
    * Help (or [[Image: New Fx Menu]] > [[Image: Help-29]]) > About Firefox
    Or download a fresh copy here:
    * https://www.mozilla.org/en-US/firefox/new/
    * (if you need a different localization): https://www.mozilla.org/en-US/firefox/all/
    Once you update, don't these articles contain the information you need?
    * [[How do I set up Firefox Sync?]]
    * [[How to update to the new Firefox Sync]]
    * [[How do I add a device to Firefox Sync?]]
    * [[How do I choose what types of information to sync on Firefox?]]
    * [[Firefox Sync troubleshooting and tips]]
    What is it you are trying to do?

  • How do I permanently remove email accounts from firefox sync on Android ics?

    I have 10 email accounts and would like to sync them all - unfortunately being new to Android and Firefox sync I started with Googlemail so I already had installed a couple of Google mail accounts when I found the Firefox options which were much simpler. I find I've now 2 email accounts each with the same 2 addresses. I thought I'd start again - i ditched Firefox on my Neuropad and unsynced my desktop, re-installed firefox on my neuropad but all the accounts reappeared. Please advise..

    Thank you so much for tolerating the confusion I created for myself. YEA
    About the "enter email address" ... gee, how did I think Firefox was going to be able to communicate with me?
    So... I go to the AOL mailbox, sign in as usual, the little box is coming down, and I click on save ... ah ha
    If I am on another computer, I will open Firefox ... enter the master password ... and move on as usual? ... because all this is on Firefox servers.
    Small confusion ... scenario ... I am to work on a computer without Firefox installed, and I may not install it. What do I do (say, to get on Yahoo mail) or anywhere else?
    Thank you many many times.

  • For how long does Firefox Sync keep synced tabs?

    I wonder if there's any time limit Firefox Sync has for storing opened URLs in the cloud? I don't have access to the computer which ran Firefox and kept its opened tabs in Firefox Sync. But now I don't see them in the "Tabs from other devices".

    Thanks, but it doesn't say anything on how long Firefox keeps tabs in the sync.

  • Pair Firefox Sync on Android with new computer

    On my PC I clicked "Set Up Sync" and then "I Have an Account" ans it asks to enter the code on my other device. So I went onto my Android Samsung Galaxy Nexus and opened Firefox.
    Went to the home screen and there is not Sync button. Only; Top sites, Your tabs from last time, Add-ons for your Firefox, and Synced Tabs.
    Going to More -> Settings -> Sync -> Account with Firefox Sync.
    It only shows an option to not sync and says when it last synced. The more only shows; Sync now, remove account and help.
    Where do I enter the code on my Android so I can set up Firefox Sync on my PC?

    Open up Firefox and go into the settings menu. From the select the option of sync. That should open up a prompt to set up sync on your Firefox device. Here is a great support article as well. https://support.mozilla.org/en-US/kb/use-sync-share-bookmarks-and-more-with-firefox-mobile?redirectlocale=en-US&redirectslug=sync-firefox-between-desktop-and-mobile

  • How secure is firefox hello?

    I cannot find any encryption settings for voice/video calling via Firefox Hello. How secure are my conversations?

    hello vidriduch, firefox hello uses webrtc as communication channel which provides peer-to-peer connections which are encrypted end-to-end out of the box...

  • How reliable is firefox sync

    Is firefox sync very very very reliable? It's difficult to get an index on how it's doing for people, as there does not seem to be any central location where people post with any support issues for it. There are reports of some issues here, but I still can't get a handle on how the current ff sync is doing for folks.
    I have been using xmarks for quite a few years. A half year ago, I fault xmarks for really fouling up my bookmarks, though it's hard to be sure it was the root of the issue. Recently I reformatted my notebook and I can't get xmarks to run the initial sync from it on the server. I've been curious about ff sync and thought maybe this would be the time to check it out. However if it is not extremely reliable might stick with xmarks. With xmarks the only usage pattern I'm confident in now is to always sync one way up to the server from my main pc, and only download full sets to the other pcs that I use.

    Yes I'm the same person. It's very difficult to interpret 'some' postings about how sync works, since the product has been in existence for years, and has just had was is purported to be a major revision.
    I suppose there is some chance that you're the same the-edmeister that responded to me on mozillazine <g>. There, you didn't post any negative comments about ff sync. But here you're guessing that I might be disappointed by it. Can you explain?
    The kind of feedback I'm hoping for is something like: there are 2 million users of the current ff sync, and very few report issues with it. Since ff is an open project I'd hope that someone in the know might be willing to offer that kind of information.
    In your case, what you posted 'over there' is that you don't organize your bookmarks, and don't save many new ones these days. To me that means you might not be the best benchmark user for a case like my intended use.
    I don't expect to hear 'facts' about ff sync, good or bad, but do hope that someone somewhere has either extensive personal experience with it, or has insight into how the project works for the probable many thousands that use it day to day.

  • Can I set up Firefox sync on Android tablet?

    I'd like to set up on Android tablet & sync to 2nd Android tablet. Please advise how I do this.
    Thank you.

    Hi, Mozilla?
    Not everyone has access to non - mobile Firefox. Please fix. I know many people who only have a phone, I'm sure they would like to be able to sync as well.
    Sincerely,
    a long time Firefox user.

  • Como faço para sincronizar mais de uma conta de email no Firefox Sync para Android?

    Olá. Tenho instalado o firefox 34.0.1 para android no celular. Tive que desinstalar por causa de um travamento e ao reinstalar perdi duas contas que eu sincronizava. Agora somente um email está sincronizado e sou obrigado a entrar nos emails por navegação comum mas perco muito tempo pois tenho que digitar conta e senha para cada uma delas. Esqueci completamente como se adicionam outras contas para serem sincronizadas. Alguém me dá um help?

    Um amigo que usa o FF para android me deu a dica de que as contas a serem acompanhadas via sync devem ser adicionadas na tela do email; Quando você recebe a notificação de mensagem, você clica sobre a notificação que abre a mensagem de email. Nessa tela, no canto superior direito tem o ícone de menu e nesse menu tem a opção de adicionar novas contas de email para sincronizar. Só clicar em adicionar. Se for uma conta existente é só preencher os campos endereço e senha e dar um ok. Você também pode criar contas novas. No meu caso a adição foi imediata pois logo em seguida recebi notificações de emails da novas contas. É isso ai; Valeu pela ajuda.

  • How to reset firefox sync?

    My device is on sync devices 5times,why

    Hi johnboy1981
    Since we can't read minds :-) we need more troubleshooting details to help you:
    # What model of Android tablet or phone are you using? What version of Android are you using (e.g. Jellybean 4.1-4.3, Kitkat 4.4, Lollipop 5.0, 5.1, etc)?
    # What version of Firefox for Android are you using? (please try the latest version which is currently FF37.0.1)
    # What did you do exactly, what happened and what did you expect? (details please! especially the steps that led to conclude "My device is on sync devices 5times," often posting a screenshot is super helpful )
    Cheers!
    ...Roland

  • What certificates does Firefox sync (for Android) use to connect to the server?

    I removed all of the CA and root authorities and would like to know which one I need to put back in order to use sync? A Few of them looked like they could stay, but there were to many that looked like just anyone could install a certificate on my tablet.
    So, I would like the entity name and sha (s) encryption keys so I can reactvate yours. Thank you.

    The technical information about the Authentication Server is documented: [https://wiki.mozilla.org/Identity/Firefox-Accounts#Auth_Server]
    Certificate Signing process specifically is done with this part of the api: [https://github.com/mozilla/fxa-auth-server/blob/master/docs/api.md#post-v1certificatesign] - I assume you would generate them there.

  • Android Firefox Sync with own Server

    Hi,
    is it possible to Sync the Android Firefox with the new 1.5 Sync Server?

    Josh182,
    Yes it is, however please take caution that the profile of the first computer will overwrite the one of the second. Sync is not meant to be a backup service. [[How to update to the new Firefox Sync]]
    For Android if you select Settings > Sync make sure the account that is attached is not Firefox Sync [deprecated].
    Add a new account after disconnecting this account. and it will take you through the login account verification/login.
    If you have any other questions, just post back!

  • If I lost my mobile, how can I deactivate firefox sync on it... without it?

    I have Firefox Sync running on my laptop, my desktop and on my smartphone too. If someone stole my phone... how can I stop Firefox Sync only on that device, from my laptop or desktop? I only know how to disable firefox sync on the device I want to disable. But if the device is not with me anymore... What should I do? If I stop using Firefox Sync on my desktop, my laptop will not sync anymore..

    You'll need to change your Sync password and then reconnect things using the new password. For more detail, read here:
    [[I've lost my phone — how do I deactivate Sync?]]

  • Cannot configure firefox sync and do not have add a device option

    I am very frustrated. I have spent a lot of time over the past two days trying to figure out how to ocnfigure Firefox sync. I am specifically trying to sync my iphone to my account. I have downloaded two apps from the Apple App store, both of which are designed to allow me to do so. When I open both of these apps they provide me with a pass code that is broken up into three sections each containing 4 letter and or number combinations, just as I see in all the articles designed to assist me with this issue. However, I open my sync dashboard and do not see ANY tab that states "Add a Device" as the articles also say. So I click on the "I am not near my computer" tab in the apps (both appear to work identically) and I am asked to enter my account, password, and sync key info. I cannot find an article anywhere that tells me what my sync key is or how to recover it if I have forgotten it~!!!@!!!!!!!! Please freaking help me!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    Apps in the Apple App Store are not from Mozilla and possibly no longer work with Firefox as Firefox has now moved from Sync to Firefox Accounts. Mozilla does not have any apps out there in the Apple app store however, 3rd parties may but they're not vetted by Mozilla.

Maybe you are looking for

  • How do I align data within a column?

    In the newly updated Numbers (Mac), I cannot find how to align data within a column.

  • Second preview monitor for presentation

    I'll try to explain. Can I mirror the desktop of my Macbook Pro to a monitor on stage to show me the presenter notes, while projecting the presentation onto a screen for the audience.

  • Charts data axis scaling problem

    Post Author: rameshp CA Forum: Charts and Graphs Hi , I work on crystal reports XI. I'm facing problem regarding scaling data axis. I have illustrated that in the following lines: case1) if i have high values (sum of bytes) like more than 600 etc. it

  • Changing mod_oc4j.conf

    Hi, Do i need to change restart the HTTP Server and 9ias after changing the $ORACLE_HOME/Apache/Apache/conf/mod_oc4j.conf?

  • Spaces bringing wrong windows to front

    Hello. I love using multiple spaces when I work. This is one of the reasons that brought me to Mac. But, there is an issue which I encounter since the beginning and which I can't stand anymore: often, when I come back to a space, the windows order is