Would Keychain be safer than Firefox Password Manager?

4

1

Theoretically speaking would Keychain be safer to use in Firefox than Firefox's own password manager? The reason I ask is because Chrome is using Keychain.

1.21 gigawatts

Posted 2012-02-05T02:20:21.047

Reputation: 1 742

see this SU question

– Raystafarian – 2012-02-05T02:34:53.250

Thanks Raystafarian. One person in the comments mentioned Keychain would be more integrated than FF password manager. I'm guessing there are advantages or disadvantages to this approach. – 1.21 gigawatts – 2012-02-05T20:50:09.967

A centralized password manager has many usability advantages though — you only need to enter the master password once, it's easier to migrate and sync passwords, and you can browse all passwords in a single interface like Keychain Access. I don't really see why people keep using Firefox over a browser with better platform integration like Safari. – Lri – 2012-02-05T22:32:36.317

Thanks LRI. I've been reading up on this. What do you think of Mozilla Sync? – 1.21 gigawatts – 2012-02-06T17:59:08.390

Firefox has keychain integration services for mac users – None – 2012-03-21T03:49:58.817

@mossy Do you mean the Keychain Services Integration extension?

– Lri – 2012-03-21T07:16:58.647

@1.21 gigawatts, I didn't get a notification of the comment — apparently the capitalization of the username has to match... I guess Firefox Sync would make sense if have to use other platforms than OS X and iOS (and don't use something like 1Password). – Lri – 2012-03-21T07:18:24.213

@Lri - It looks like they added an auto-complete since I last visited to help people with this. I do have to use other platforms. – 1.21 gigawatts – 2012-03-21T11:25:11.533

Answers

5

Keychain is encrypted by default whereas Firefox password manager is not encrypted by default. You can use a master password with Firefox password manager at tools - options - security tab - use master password but ultimately FF password manager is nearly 100% unsafe without a master password

Raystafarian

Posted 2012-02-05T02:20:21.047

Reputation: 20 384

1Note to self: Apply master password – 1.21 gigawatts – 2012-02-05T20:52:06.487

2

If you don't use a master password with Firefox, anyone with access to your computer can currently install an extension like Password Exporter and export all saved passwords in clear text.

Lri

Posted 2012-02-05T02:20:21.047

Reputation: 34 501

1yikes! got it. note to self: apply master password – 1.21 gigawatts – 2012-02-05T20:45:00.373