Inability to fully disable autocomplete security issue
Reported by
pie...@lgse.com,
Nov 11
|
||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36 Steps to reproduce the problem: 1. Attempt to use <Form autocomplete="off"> or <Form autocomplete="new-password" What is the expected behavior? Autocomplete for said form is supposed to be turned off completely. What went wrong? The fact that we cannot disable autocomplete entirely is a security issue. If multiple users share the same computers with a single profile, other users can use the autofill functionality to login using another user's stored credentials. Did this work before? Yes 66 Does this work in other browsers? N/A Chrome version: 70.0.3538.77 Channel: stable OS Version: 10.0 Flash Version: Please enable the developer to disable autocomplete/autofill entirely.
,
Nov 12
,
Nov 12
pierre@ - Thanks for filing the issue...!! Could you please provide a sample test file or url to test the issue from TE-end. This will help us in triaging the issue further. Thanks...!!
,
Nov 13
@krajshree this issue cannot be replicated with a sample test file unfortunately. In order for autofill to save the credentials there needs to be some sort of a backend infrastructure in place. I can host the page and put a link to it here if that's allowed. Otherwise I don't know how I could proceed to put a valid test case together.
,
Nov 13
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 13
I added a test case online hosted on github.io Go to: https://lgse.github.io/chrome-issue-904180/ Then enter a fictitious username/password and hit submit, you will then be prompted to save the password by chrome for future autofill. Go back to the original page https://lgse.github.io/chrome-issue-904180/ and you will see your credentials being autofilled into the form despite having the autocomplete="off" tag appended. For the record, I've been following this issue for quite some time now and it seems as if Chrome has made it impossible for developers to disable autofill entirely and this is a security issue as I stated in my original post. I'm fully aware that it was done to provide a better experience to the end user. In this case, I'm building an enterprise grade applications and the autofilling violates security policies. Please enable the developer to stop autofill behavior entirely.
,
Nov 13
,
Nov 13
Tested the issue on win-10 using chrome reported version #70.0.3538.77 and latest canary #72.0.3608.0. Attached a screen cast for reference. Following are the steps followed to reproduce the issue. ------------ 1. Navigated to https://lgse.github.io/chrome-issue-904180/ 2. Entered a fictitious username/password and hit submit. 3. Saved the password. 4. Navigated back to the original page https://lgse.github.io/chrome-issue-904180/ 5. Observed that credentials have been autofilled into the form. Note: Same behavior is observed from M-60 chrome builds. pierre@ - Could you please check the attached screen cast and please let us know if it is the issue being observed. If not then please provide a screen cast for better understanding of the issue and please let us know if anything missed from our end in reproducing the issue. Thanks...!!
,
Nov 13
Yes that is the problem @krajshree! Thank you for the screencast.
,
Nov 13
Thank you for providing more feedback. Adding the requester to the cc list. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 13
Unfortunately, we can't implement this for the reason you mentioned above ("it was done to provide a better experience to the end user"). We are following the Priority of Constituencies here (https://www.w3.org/TR/html-design-principles/#priority-of-constituencies).
What's possible, is to use policies to disable the password manager in an enterprise scenario: https://www.chromium.org/administrators/policy-list-3#PasswordManagerEnabled
Maybe that helps to a certain degree. Sorry that I cannot give better news.
,
Nov 13
This is kind of crazy that you guys will basically just force down our throat what you think is best without giving any option to turn it off whatsoever. There’s valid scenarios where it can and should be turned off. And no, that doesn’t help me, how exactly am I supposed to go on the end user’s computer and turn that off? Ugh |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by tkent@chromium.org
, Nov 12