Live data from Hacker News

The war against autocomplete=off (2013)

blog.0xbadc0de.be

11–20 of 78 posts

Re: The war against autocomplete=off (2013)

#11
This drives some of our customers nuts because autocomplete has the annoying tendency in the most recent Safari of overwriting prepopulated fields - users end up losing configurations over this.

Otherwise I can see the benefit of ignoring the setting, perhaps, but we need consistent default behavior (chance would be a fine thing!). I don't want to be telling my customers that they should switch off autocomplete as a user shouldn't need to configure a browser to use a website!

Re: The war against autocomplete=off (2013)

#12
post #3

I've run into the problem of web services not letting me store passwords. The reality is, if you let my password manager (safari jacks into OS X's keychain system) keep track of things, I'm going to use the random 12-digit alphanumeric password my password manager provides me. If you don't, I'm either going to use my shitty "brain" password or put it in my password manager anyway and just copy-paste it manually. Than…

Where is the toggle in iOS? That would be really useful.

Re: The war against autocomplete=off (2013)

#13
This article uses "password managers" ambiguously. In my opinion, a browser is a terrible password manager because of what is stated in the "pros" section of the article. My advice aligns with others who have replied here - get a real password manager such as 1password and allow autocomplete="off" to do what it is supposed to do.

Re: The war against autocomplete=off (2013)

#14
The original article fails to take into account the larger population. The basic password managers in browsers are huge security holes. The one in FF does not use a master password by default, so anyone could look at an unattended computer and see all stored passwords with a few clicks. The article mentions an old JavaScript attack on the passwords as well (but then dismisses the threat, since that one hole was patched).

So the problem really is that the browsers pushed insecure features out to the masses, and many people adopted them. The number of people in the general population who use a password manager is low (obviously it is high here on HN). So think of the autocomplete=off flag as a flag to make sure you are using a competent password manager, one that recognizes the problem and then overrides the flag. Sounds like Safari and IE 11 are already doing that, so hopefully they fixed the problems of the early password managers.

Re: The war against autocomplete=off (2013)

#15
post #14

The original article fails to take into account the larger population. The basic password managers in browsers are huge security holes. The one in FF does not use a master password by default, so anyone could look at an unattended computer and see all stored passwords with a few clicks. The article mentions an old JavaScript attack on the passwords as well (but then dismisses the threat, since that one hole was patch…

Compared to weak passwords, phishing and a myriad other threats, how likely is that someone will walk up to my computer and copy a password? How likely are they to have a true criminal intent rather than a prank on their mind?

And when your machine is compromised or otherwise controlled by an untrustworthy third party, you lost anyway.

Re: The war against autocomplete=off (2013)

#16
post #3

I've run into the problem of web services not letting me store passwords. The reality is, if you let my password manager (safari jacks into OS X's keychain system) keep track of things, I'm going to use the random 12-digit alphanumeric password my password manager provides me. If you don't, I'm either going to use my shitty "brain" password or put it in my password manager anyway and just copy-paste it manually. Than…

Where is the toggle in iOS? That would be really useful.

As of OS X 10.9.2 and iOS 7.1 the setting has been removed and autocomplete=off is always ignored.

Re: The war against autocomplete=off (2013)

#17
> Please note that if you combine this policy and at the same time disable copy and paste into the password fields (I look at you, Blizzard!), I hate you.

oh man. disabling paste is the worst, because it breaks keypassx. (Apple did this last I checked!)

turbotax did that as well last year, this year they made it sane again. Luckily there's a firefox about:config setting you can do to not let websites hijack / block your clipboard events.

Re: The war against autocomplete=off (2013)

#18
post #6

The issue may be moot--IE 11 ignores autocomplete=off. And in any case, for the cases where this setting is effective, it doesn't break password managers--just set your password manager to not fill the fields, but use copy and paste for the password. [Edit - spelling]

I think you mean "moot", not "mute".

Re: The war against autocomplete=off (2013)

#19

I don't think I've run into a situation where LastPass has been unable to auto-fill a form. Is this a feature of LastPass, or have I just not gone to sites that disallow autocomplete?

It's the latter. I use LastPass too, and there's one particular site where it doesn't autofill, because of autocomplete=off. It's just one site, but incredibly annoying because I use it often multiple times per day (and of course it doesn't allow me to stay logged in either.)
Post reply on HN