Form history sometimes remembers credit card details

Bug #801616 reported by Christopher Neville-Smith
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

This isn't a bug report as such, but this is a potential security issue. Unfortunately, I don't know if there's an easy answer to this.

I only use the internet for purchases sparingly, but I've noticed that on some web pages that remember credit/debit card details, Firefox remembers the card number and security code as form history - and also, depending on how the web page is designed, the expiry date. It's an easy matter to clear private data, but this isn't something a newbie is likely to think of doing. (Okay, I know that Ubuntu by default requires you to log in with a password before you can get anywhere near the data kept by Firefox, but I worry that if, say, a laptop was stolen, it wouldn't be too hard to by-pass the password protection and access this data.)

I'm happy to give examples of web sites that behave this way, but I'd rather not leave it somewhere publicly accessible. (Is there an e-mail address I could privately send that?)

Is there any way firefox can be set up to not remember credit card details you have entered by default?

ProblemType: Bug
DistroRelease: Ubuntu 11.04
Package: firefox 5.0+build1+nobinonly-0ubuntu0.11.04.2
ProcVersionSignature: Ubuntu 2.6.38-8.42-generic 2.6.38.2
Uname: Linux 2.6.38-8-generic x86_64
Architecture: amd64
Date: Fri Jun 24 16:14:11 2011
FirefoxPackages:
 firefox 5.0+build1+nobinonly-0ubuntu0.11.04.2
 flashplugin-installer 10.3.181.26ubuntu0.11.04.1
 adobe-flashplugin N/A
 icedtea-plugin 1.1~20110420-0ubuntu1.1
InstallationMedia: Ubuntu 10.10 "Maverick Meerkat" - Release amd64 (20101007)
ProcEnviron:
 LANGUAGE=en_GB:en
 LANG=en_GB.UTF-8
 SHELL=/bin/bash
SourcePackage: firefox
UpgradeStatus: Upgraded to natty on 2011-05-08 (47 days ago)

Revision history for this message
Christopher Neville-Smith (chris-neville-smith) wrote :
security vulnerability: yes → no
visibility: private → public
Revision history for this message
Paul White (paulw2u) wrote :

Christopher,

We are sorry that we do not always have the capacity to review all reported bugs in a timely manner. You reported this bug in 2011 and there have been many changes in Ubuntu since that time.

Do you still see this problem in the currently supported releases of Ubuntu and Firefox? Please let us know if you do.

If we do not hear from you the bug report will close itself in approximately 60 days time.

Thank you for helping make Ubuntu better.

Paul White
[Ubuntu Bug Squad]

Changed in firefox (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for firefox (Ubuntu) because there has been no activity for 60 days.]

Changed in firefox (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.