Thunderbird stored OpenPGP secret keys without master password protection
mozilla.org
mozilla.org
You logging into your computer unlocks your keyring, which unlocks the secret your browser uses to encrypt things like passwords....
However looking at my keyring on Linux, I see secrets for Chrome, I do not see secrets for firefox... Which I find extremely surprising and disappointing...
If you're not logged in, and you don't encrypt your files, then someone getting access to saved passwords in addition to all your files is worse than just getting access to all your files, but not by a huge amount.
If you're not logged in and do encrypt your files then nobody will have access.
https://www.theguardian.com/technology/2013/aug/07/google-ch...
Protecting this key would require to ask a password to the user.
By default there are none, but users who use gpg are aware of security and would generally set a master password.
Or do you mean setting a master password for the key itself outside of Thunderbird?
A few years ago, that included complex passwords that lock in 3 wrong attempts among other things.
Worst part is that the rules tend to infect other parts of the business if people do stuff incorrectly.
In OpenPGP the thing you call a "key" is actually many keys: there is a primary one and whatever number of subkeys. Subkeys are those that are actually used in day-to-day encryption and signing activity, and that you need on your computer. Primary keys are used to sign subkeys and other people's keys, but you don't need them for day-to-day activities, so you can keep them in a separate storage that is not normally attached to your computer.
If your computer gets compromised you have to revoke subkeys, but you can keep the primary key (unless you attached the cold storage to your computer while it was compromised). This makes the rotation much less painful than if you have to revoke your primary key, which implies also re-establishing signatures and trust with other people.
If you search for "gpg subkeys" you will find a few tutorials.
Even more secure is to keep the primary key offline and the subkeys in a security module, like Yubikey, Gnuk or Nitrokey Start. That makes everything much more secure, and you can easily carry your keys to other computers, knowing that when you detach your security module that computer won't have access to your keys any more.