Comments (11)
Doesn't appear to be related to NoScript then, and not all of these pages are calling Facebook. I'm not going to install that Alpha but it only seems to be avoiding it having to prompt to save everytime. The real issue is it's detecting form submissions that aren't there or are not user-triggered, and also mis-interprteting non-auth fields as auth fields.
There may well be other changes in the alpha which affect these various areas.
I have looked at all the links supplied here and none appear to detect a submission while just viewing the page using Kee 2.0.0.12.
<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=579216298929618&ev=PageView&noscript=1"/
This code sample is not really related to the NoScript Firefox add-on - it's just standard web page (HTML) code to allow different behaviour in browsers that have scripts disabled. How NoScript add-on handles that is probably highly complex and unrelated to the issues with KeeFox.
Please also see this standard message below so that anyone interested can understand if no activity occurs until next year and why at that time we may close the issue.
First, please see http://keefox.org/news/detail/2017/09/19/introducing-kee-20
The issues that affect Kee 2.0 will be different to KeeFox 1.7 and even where the same issues affect both versions, the cause will usually be different.
This issue will not be addressed here unless it is specific to Thunderbird or a serious problem affecting Firefox 52 ESR. Please get in touch privately if you find a security flaw regardless of which Mozilla application it affects to ensure a process of responsible disclosure can be followed.
If the issue is still relevant in Kee 2.0 please raise an issue in the new repository. For issues relating to the web browser add-on, or when you are not sure, please use https://github.com/kee-org/browser-addon/issues. For issues that affect the KeePass plugin (KeePassRPC) please use https://github.com/kee-org/keepassrpc/issues
I appreciate this might be disappointing for some people watching tickets involving things you feel would be great improvements or fix irritating bugs and limitations with KeeFox 1.x but I hope you'll understand that it's not wise to spend time on a version of the add-on which will cease to function in the latest version of Firefox in a month.
If you want to express an opinion or emotion relating to this comment, please use the "reaction" buttons rather than writing a new comment if possible - that will make it easier to tidy things up in 2018 so we can spend more time improving KeeFox instead of managing project admin.
If you'd like to comment or ask about the more general migration plan and reasoning for Kee 2.0, please join in the discussion at kee-org/browser-addon#1 if there is no more specific issue or forum for discussion.
Thanks,
Chris
from keefox.
This happens to me all the time as well. Very frustrating.
from keefox.
I can confirm this, it is occurring too many times. For example when I post something in XDA Forums (forum.xda-developers.com) I am prompted to save a password. And this is only the first that comes up to my mand. Avaiable to share more information where needed.
from keefox.
Confirmed happening for me as well on Firefox ESR 54 with KeeFox 1.7.2. It was updated 9/13/17 and I think that's when this became so frequent. I'm running KeePass 2.36. All under Win7 Ultimate 64bit.
I get this for pretty much any action that involved submitting a form, even just search forms. I saved some of the entries it wanted to create and they always seem to have a long random number for just the username, nothing else. I then looked at the source code for one of the pages that triggered it, and noticed the same number was in a script:
<noscript><img height="1" width="1" style="display:none"
src="https://www.facebook.com/tr?id=579216298929618&ev=PageView&noscript=1"/
</noscript>
I do use NoScript, anyone else with this issue using NoScript? I'm wondering if this is always triggered by Facebook as well, that "?id=" seems like a likely culprit (I don't use Facebook).
from keefox.
I'm not using NoScript, the issue appears every time there is a form interaction by any website.
EDIT: Good news, the new WebExtension version in development does cirumvent this bug.
Alpha 8 here
Less intrusive save password interface: We always allow the user to request to save the login from the main browser popup panel but we no longer auto-display a prompt to save the login.
from keefox.
I'm not using NoScript either.
For debugging purposes, here are a couple of pages that consistently trigger the "save password?" dialog for me upon page load. These are all pages on sites where I don't have any kind of user account, so there's been no manual interaction with forms on them by me or password records saved in my KeePass database.
- http://www.baltimoresun.com/news/nation-world/ct-las-vegas-shooter-motive-20171003-story.html
- https://thewirecutter.com/reviews/best-small-tv/
from keefox.
@jalefkowit That Baltimore page doesn't triggert it for me, but the Wirecutter page does. It ends up creating an entry (if I allow it) with, again, a random string of numbers for the username.
And of the links @antimatter84 provided, the Recipe page does do it but not the motor sports page.
Doesn't appear to be related to NoScript then, and not all of these pages are calling Facebook. I'm not going to install that Alpha but it only seems to be avoiding it having to prompt to save everytime. The real issue is it's detecting form submissions that aren't there or are not user-triggered, and also mis-interprteting non-auth fields as auth fields.
from keefox.
Also confirming the problem. Posted this on the keefox forum, but it is apparently abandoned. Tumbleweeds. Crickets.
So, here is a good example of what we are all talking about:
https://www.newscientist.com/article/2144721-chinas-quantum-submarine-detector-could-seal-south-china-sea/
Just pulling up the website with keyfox installed produces the unexpected and undesirable behavior:
**
**
from keefox.
@luckyrat, Thanks for the updates! I didn't know about Kee 2.0, and I agree this isn't an issue worth focusing on if it's in an older version. The constant pop-ups are an irritation, they don't impact functionality.
Security-wise, the only concern I'd have would be if this could somehow be leveraged in combination with XSS or similar, but I doubt that'd have of a footprint to be something to worry about.
from keefox.
Hi,
I somewhat solve or bypass this problem by installing Ghostery extension.
I guess it block the script or form that cause this problem. Hope this can help some of you.
from keefox.
Following the recent announcement of the end of critical security patch support for this old software - https://forum.kee.pm/t/keefox-critical-security-support-ends-30th-september-2020-kee-is-unaffected/3219 - this issue has been automatically marked as stale. We will soon close this issue and then archive this repository in early October 2020.
If you think that the issue contents may still be relevant to the actively maintained Kee project, the successor of KeeFox, please search the community forum for help and post a new topic if appropriate: https://forum.kee.pm
Please do not reply to this comment / notification - it won't be seen.
from keefox.
Related Issues (20)
- Backward compatibility of KeePassRPC HOT 1
- issues with keefox since thunderbird 52 HOT 3
- Koho KeeFox Forum new topic button missing HOT 3
- KeePassRPC plugin update very hard to find HOT 9
- Firefox 57.0b3 and soon final 57 will be not supported HOT 2
- Latest version of KeePassRPC but Keepass keeps asking to update HOT 2
- This add-on could not be installed because it has not been verified HOT 1
- Help with KeeFox HOT 2
- Often show up a "Authorise a new connection" window HOT 3
- Keefox changed to kee and is now unusable HOT 3
- Problem with Kee and Bitbucket FF57 HOT 2
- Latest Kee 2.0.0.25 fails to fill credentials with Firefox 57 on specific site HOT 1
- TB58 freezes with KeeFox "options" HOT 5
- REQUEST : KeeFox autofill password field with last generated password HOT 1
- Password icon appears in normal text fields HOT 1
- [Solved] authorise a new connection page is blank screen, any fix to this? HOT 1
- KeeFox toolbar missing since Palemoon 28! HOT 1
- Obtrusive update notification
- FF 72.0.2, KeePass 2.44, KeeFox 3.2.7 and RPC Plugin 1.10.0 cause KeePass to crash HOT 1
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from keefox.