Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

True, if you accidentally lost data, this suggests the documentation should be better. But this is not entirely changing:

class-A: data assigned to this class can be recovered, even if the user forgets their password, by proving control over an email address and resetting the account. It can also be read by Mozilla (since it runs the keyserver and knows kA), or by the user's IdP (by resetting the account without the user's permission).

class-B: data in this class cannot be recovered if the password is forgotten. It cannot be read by the IdP. Mozilla (via the keyserver) cannot read this data, but can attempt a brute-force dictionary attack against the password.

- https://github.com/mozilla/fxa-auth-server/wiki/onepw-protoc...

We do not yet know which data will be assigned to which category by default, but it is likely that saved-passwords will go into class-B, and many other datatypes will default to class-A. There will be an option to put all data into Class-B.

- https://wiki.mozilla.org/Identity/AttachedServices/Architect... (not sure if out of date)

...and for good reason, because since Mozilla presumably wants to avoid being required to hand over account data by governments to the greatest extent possible. Being able to reset your password via email necessarily makes it possible for Mozilla to decrypt that data.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: