pfn / passifox

Extensions to allow Chrome and Firefox (4.0+) to auto form-fill passwords from KeePass (requires KeePassHttp)
GNU General Public License v3.0
903 stars 185 forks source link

passifox and chromeipass not using updated password after password change #99

Open ashmandias opened 12 years ago

ashmandias commented 12 years ago

I recently changed my password for a website. If I enter it manually, I can log in. If I copy/paste it from KeePass, it works. If I select "fill username and password", it appears like a much longer password is being entered (many many more stars) and my authentication is refused. It's almost like it is caching the wrong password, or something. I have tried to disable/reenable the plugins, I have removed and reauthorized the use of the password for the given website, restarted both the browsers, and KeePass itself, with no luck.

Thanks!

pfn commented 12 years ago

Search your database for entries with the same domain, it’s likely it’s picking up the wrong entry

From: ashmandias notifications@github.com Sent: ‎November‎ ‎1‎, ‎2012 ‎11‎:‎55‎ ‎AM To: pfn/passifox passifox@noreply.github.com Subject: [passifox] passifox and chromeipass not using updated password after password change (#99)

I recently changed my password for a website. If I enter it manually, I can log in. If I copy/paste it from KeePass, it works. If I select "fill username and password", it appears like a much longer password is being entered (many many more stars) and my authentication is refused. It's almost like it is caching the wrong password, or something. I have tried to disable/reenable the plugins, I have removed and reauthorized the use of the password for the given website, restarted both the browsers, and KeePass itself, with no luck.

Thanks!

— Reply to this email directly or view it on GitHub.

ashmandias commented 12 years ago

It appears that this particular URL is unique in my database. I do retain the history of password changes, but that should not cause issue -- should it?

ashmandias commented 12 years ago

A simple test (by deleting my history of changes) shows that I was correct on that assumption.

ashmandias commented 12 years ago

Interesting. I changed my password to a shorter one, and it is working....

pfn commented 12 years ago

passifox and chromeipass shouldn’t have any issues with password length; are you going over 16 characters maybe? (possible, I suppose, but shouldn’t be any issues)

From: ashmandias notifications@github.com Sent: ‎November‎ ‎1‎, ‎2012 ‎3‎:‎28‎ ‎PM To: pfn/passifox passifox@noreply.github.com CC: Perry pfnguyen@hanhuy.com Subject: Re: [passifox] passifox and chromeipass not using updated password after password change (#99)

Interesting. I changed my password to a shorter one, and it is working....

— Reply to this email directly or view it on GitHub.

ashmandias commented 12 years ago

Looking into the issue, other people have reported that battle.net doesn't play well with passwords longer than 16 characters. Looking into it, I was using 32 -- when passifox entered the password, it added 32 dots. When I used the copy/paste method, it only added 16. It appears that Battle.net was jerking around the input field -- likely ignoring the last 16 characters when pasted, but not added through a plug in.....

stefpeto commented 12 years ago

I'm a new user and i can confirm this issue. I changed a password, it was 32 symbols. After i realized i'm being stupid i changed it for a shorter one - 8, after that i log out and enter the login screen again. It fills the username and a long password (the old 32 bit one) and fails to login, if i paste manually the new password it works of course. So after i investigated the issue i found that if i restart the browser, everything is working fine, no old passwords are typed in. So there is a problem. Im using PassIFox/Nightly 19.0a1

ps. By the way i love the extension, its much better than KeeFox in my opinion, its better integrated with the browser, it doesn't have a ugly bar on the top that sits there always and asks you stupid questions, and i love that it remembers different accounts for one website unlike KeeFox. Its easy to setup if you can read, so i cant get why is all that bitching in the negative reviews here. Anyway, i love it, I would love to see functionality like generating passwords directly from the register page of a website and then asking you to save the newly typed credentials in the databade i think that wold be cool.