Bug#790498: iceweasel: upgrading from jessie makes all passwords in the password manager invalid

Mike Hommey mh at glandium.org
Sun Jul 12 22:46:29 UTC 2015


tag 790498 unreproducible
severity 790498 important
thanks

On Mon, Jun 29, 2015 at 11:28:02PM +0300, Török Edwin wrote:
> Package: iceweasel
> Version: 38.0.1-5
> Severity: grave
> Justification: causes non-serious data loss
> 
> Dear Maintainer,
> 
> I have upgraded Iceweasel from jessie (31.7.0esr-1~deb8u1) to testing and
> suddenly none of my saved passwords worked, and the password manager doesn't
> even show all the websites
> that have stored passwords in the jessie version.
> 
> I am still able to login to my websites if I manually type in the correct
> password (and tell iceweasel to save the updated passwords),
> however using the prefilled passwords doesn't work, and looking up the
> passwords in the password manager and pressing show password
> reveals the wrong password.
> 
> When I press show passwords most passwords look like base64 (a-zA-Z0-9+/)
> whereas the original passwords had a combination of alphanumeric and symbols.
> 
> If I downgrade to the version in jessie then the passwords work correctly again
> (including the ones overwritten by the testing version of iceweasel).
> 
> I tried to create a new account just for the purpose of testing this bug, but
> the site and associated password doesn't show up at all when upgrading
> iceweasel (and is visible again when downgrading),
> haven't figured out so far what makes a site/user/password "survive" the
> upgrade.
> 
> I've marked the bug as 'causes data loss', because initially that is what I
> thought happened when none of the passwords worked, and I'm still not sure how
> safe the data in the password manager is
> across upgrades/downgrades (so far downgrading has restored all passwords, but
> I can't be sure it'll stay that way).

Your comment in upstream bug says that forcing a new upgrade of the
signons store worked, so it's really not clear what went wrong the first
time.

Mike



More information about the pkg-mozilla-maintainers mailing list