Issue metadata
Sign in to add a comment
|
Autocomplete on password fields
Reported by
joakim.j...@storywars.net,
Jan 26 2018
|
||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 Steps to reproduce the problem: 1. Go to twitter for example 2. Try to change your email 3. You need to verify your email using your password 4. The form has autocomplete="off" but you still get autocompleted passwords which kills that security. What is the expected behavior? Not to show autocompleted passwords on fields that are for verifying password after you are logged in! What went wrong? Not to show autocompleted passwords on fields that are for verifying password after you are logged in! Did this work before? Yes Not sure Does this work in other browsers? N/A Chrome version: 63.0.3239.132 Channel: n/a OS Version: OS X 10.13.2 Flash Version: I agree with all your other decisions so you do a good job but this one needs a fix, I understand the want to autocomplete but there should still be a possibility to turn it off for security reasons. I understand that if someone is still on your computer, then that is not the most secure system either but I still feel that this is not the best solution.
,
Jan 26 2018
Unfortunately, I have to close this. Here is the argument: https://dev.chromium.org/Home/chromium-security/security-faq#TOC-Why-does-the-Password-Manager-ignore-autocomplete-off-for-password-fields- If you use long, random and unique passwords for every website, you have to be able to rely on the password manager filling passwords for you. |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by meh...@chromium.org
, Jan 26 2018