New issue
Advanced search Search tips

Issue 638634 link

Starred by 1 user

Issue metadata

Status: Available
Merged: issue 674151
Owner: ----
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 2
Type: Bug

Blocking:
issue 812595



Sign in to add a comment

Password generation bubbled prompted for SSN fields

Project Member Reported by bettes@chromium.org, Aug 17 2016

Issue description

Chrome stable
Version 52.0.2743.116 (64-bit)

What steps will reproduce the problem?
(1)https://www.usaa.com/inet/ent_proof/proofingEvent?action=Init&event=forgotOnlineId&wa_ref=pub_auth_nav_forgotid
(2)Select social security number to prompt SSN input fiel
(3)select first box labeled "Enter" 

What is the expected output?
Chrome should be smarter about when to surface password generation. The SSN fields are contained within a table that have IDs like "Social Security Number or Tax ID Number". 

Maybe we scan associated labels or IDs around a specific input field and if we hit a "Password" label/ID, we surface the pop-up, and if not then we skip the opportunity. 

A consistent false positive (I've run into these alot) is worse then never appearing in the first place.  

What do you see instead?
Chrome surfacing password generation for irrelevant fields like SSN

 

Comment 1 by vabr@chromium.org, Aug 18 2016

Labels: Hotlist-Polish OS-All
Status: Available (was: Untriaged)

Comment 2 by kolos@chromium.org, Mar 9 2017

Mergedinto: 674151
Status: Duplicate (was: Available)

Comment 3 by kolos@chromium.org, May 24 2017

Blocking: 674151
Status: Available (was: Duplicate)

Comment 4 by kolos@chromium.org, Feb 16 2018

Blocking: -674151 812595
PasswordAutofillAgent recognizes that the field is not an actual password, but a SSN. PasswordGenerationAgent should know about that.  

The server-side triggers generation because two identical password field is a strong signal of a password creation field. 
another example of generation on SSN field https://access.paylocity.com/Register

Proposal: if a field name/id/label contains "ssn" as substring, suppress generation.

Sign in to add a comment