Re: Login forms autofill
Richard Z <[email protected]> Tue, 14 Nov 2017 23:27:12 +0100
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Nov 14, 2017 at 12:02:40PM +0100, WhiteWinterWolf wrote: ... ... > - Would even Firefox be modified to handle automatically filled > authentication forms as a special case and turn some properties read-only > from JavaScript, potentially breaking some websites by the way, this > wouldn't prevent attacks relying on malicious or leaked CA certificates for > instance, + any additional techniques than the ones mentioned above which > most likely *will* be discovered in the future, as long as browsers provide > such functionality. in addition to all security risks there is also a potential privacy issue, websites will know that its you as soon as the login (or any other) form is autofilled even long before you hit login. Yet another method of tracking. > - Or you can simply require the user to click on an authentication form to > fill it. Problem solved. > > In my opinion, the second option is both more secure, easier to implement > and more user friendly. But that's just my opinion. makes sense in todays world. Richard -- Name and OpenPGP keys available from pgp key servers