Master Password

How to set a Master Password

To secure the passwords saved by Firefox Password Manager it is recommended to set a Master Password:

  • Go to Firefox preferences page
  • Change to the "Security" tab and
  • Check "Use a master password".

Without a Master Password your passwords will still be stored encrypted, but anyone with access to your computer will be able to use the encryption key to reveal your passwords or login with your authentication data.

With a Master Password set you will have to authenticate once each Master Password session (by default until you close the browser window and restart Firefox) before you can access your saved passwords or login with Secure Login.

See also How to create secure passwords?

Advanced Master Password settings

You can access advances settings for Firefox Master Password if you copy+paste the following in your address bar and hit the Return/Enter key:
chrome://pippki/content/pref-masterpass.xul
This will open up a dialog where you can

  • Change your Master Password
  • Set a different timeout for the Master Password session and
  • Reset your Master Password.

Manual logout of the Master Password session with Firefox "Clear Private Date" feature

Using Firefox "Clear Private Date" feature you can manually log out of the Master Password session:

  • Go to "Tools" => "Clear Private Data..." (or hit Ctrl+Shift+Del on your keyboard).
  • Make sure "Authenticated Sessions" is checked.
  • Click on "Clear Private Data Now" to logout of the Master Password session.

After logging out of the Master Password session you will have to re-authenticate if you want to access the saved passwords or login with Secure Login.
This makes it possible to let friends browse the web without having to restart Firefox or giving them access to your saved passwords.

Manual logout of the Master Password session with Secure Login

A click with the middle mouse button (e.g. a "clickable" scroll wheel) or holding down the Control key while clicking with the left mouse button on the toolbar button (or the status bar icon) will log you out of the Master Password session, showing a notification of the successful logout:

screenshot-04

Note that the notification will also show up if you aren't logged in to the Master Password session or if you didn't set up a Master Password.