Browser auto-fill phishing
github.com
Browser auto-fill phishing
1–10 of 150 posts
Re: Browser auto-fill phishing
#2Re: Browser auto-fill phishing
#3Re: Browser auto-fill phishing
#4I think this means browsers will never fix this issue. I won't be using auto-fill on untrusted webaites.
Re: Browser auto-fill phishing
#5I saw this example doing the rounds on twitter. Hopefully the chrome devs notice the noise and move up the priority on fixing / addressing it.
Re: Browser auto-fill phishing
#6Wow, great demonstration. I'd never thought about this being exploited. I wonder if the fix could be something as simple as the browser only allowing non-hidden [Edit: "not visible to the user", I should have said, as this does not appear to auto-fill ] fields to be auto-filled. Otherwise, a warning about what auto-fill information (IE "Your name and credit card information are going to be submitted, continue?") has…
Your second idea about an auto-fill warning would be better. Maybe a simple footer warning or something.
Re: Browser auto-fill phishing
#7Wow, great demonstration. I'd never thought about this being exploited. I wonder if the fix could be something as simple as the browser only allowing non-hidden [Edit: "not visible to the user", I should have said, as this does not appear to auto-fill ] fields to be auto-filled. Otherwise, a warning about what auto-fill information (IE "Your name and credit card information are going to be submitted, continue?") has…
Maybe some feedback from the browser detailing which datapoints were autofilled. I don't know...