New issue
Advanced search Search tips

Issue 806229 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jan 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Autocomplete on password fields

Reported by joakim.j...@storywars.net, Jan 26 2018

Issue description

UserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36

Steps to reproduce the problem:
1. Go to twitter for example
2. Try to change your email
3. You need to verify your email using your password
4. The form has autocomplete="off" but you still get autocompleted passwords which kills that security.

What is the expected behavior?
Not to show autocompleted passwords on fields that are for verifying password after you are logged in!

What went wrong?
Not to show autocompleted passwords on fields that are for verifying password after you are logged in!

Did this work before? Yes Not sure

Does this work in other browsers? N/A

Chrome version: 63.0.3239.132  Channel: n/a
OS Version: OS X 10.13.2
Flash Version: 

I agree with all your other decisions so you do a good job but this one needs a fix, I understand the want to autocomplete but there should still be a possibility to turn it off for security reasons. I understand that if someone is still on your computer, then that is not the most secure system either but I still feel that this is not the best solution.
 

Comment 1 by meh...@chromium.org, Jan 26 2018

Components: -Blink>Input UI>Browser>Passwords

Comment 2 by battre@chromium.org, Jan 26 2018

Status: WontFix (was: Unconfirmed)
Unfortunately, I have to close this. Here is the argument: https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-does-the-Password-Manager-ignore-autocomplete-off-for-password-fields-

If you use long, random and unique passwords for every website, you have to be able to rely on the password manager filling passwords for you.

Sign in to add a comment