Live data from Hacker News

The war against autocomplete=off (2013)

blog.0xbadc0de.be

61–70 of 78 posts

Re: The war against autocomplete=off (2013)

#62
post #22

Earlier quoted context omitted.

Compared to weak passwords, phishing and a myriad other threats, how likely is that someone will walk up to my computer and copy a password? How likely are they to have a true criminal intent rather than a prank on their mind? And when your machine is compromised or otherwise controlled by an untrustworthy third party, you lost anyway.

Nobody is arguing that autocomplete is a threat on par with phishing.

However, auto complete is a great way to fight phishing. It's easy to tell people you think your on website X but your password never shows up your probably on a different site. And the simple fact there password is not there is enough to get most people get somewhat paranoid.

So, for most people you trade a near meaningless threat to fight a major one which tends to be a net win.

Re: The war against autocomplete=off (2013)

#63
Someone was showing me Capital One 360 (formerly ING), which uses an onscreen PIN pad that you either have to click with your mouse, or type using a randomly generated mapping. The idea is to thwart keystroke loggers, but it's totally infuriating.

Re: The war against autocomplete=off (2013)

#64
post #14

The original article fails to take into account the larger population. The basic password managers in browsers are huge security holes. The one in FF does not use a master password by default, so anyone could look at an unattended computer and see all stored passwords with a few clicks. The article mentions an old JavaScript attack on the passwords as well (but then dismisses the threat, since that one hole was patch…

> So think of the autocomplete=off flag as a flag to make sure you are using a competent password manager

No, what happens is that autocomplete=off flag is a flag to make sure you are using your brain as a password manager, which experience has shown to be a terrible idea.

Instead of a browser password manager that can help make your passwords unique per site and comprised of random characters, users are forced to use passwords from their head, likely sharing them between sites. Someone coming to your unattended computer isn't nearly the threat of you using a simple and short password across every site you visit, including the sites that end up with a stolen passwords database or have a moronic password recovery option.

Re: The war against autocomplete=off (2013)

#65
post #3

I've run into the problem of web services not letting me store passwords. The reality is, if you let my password manager (safari jacks into OS X's keychain system) keep track of things, I'm going to use the random 12-digit alphanumeric password my password manager provides me. If you don't, I'm either going to use my shitty "brain" password or put it in my password manager anyway and just copy-paste it manually. Than…

So, does Safari manage to autocomplete the PayPal password for you?

Re: The war against autocomplete=off (2013)

#66

Someone was showing me Capital One 360 (formerly ING), which uses an onscreen PIN pad that you either have to click with your mouse, or type using a randomly generated mapping. The idea is to thwart keystroke loggers, but it's totally infuriating.

The worst part is, it doesn't even thwart keyloggers very well! It's not uncommon for password stealing malware to detect when the user is viewing a site that uses a "PIN pad" login of this type, and start taking screenshots surrounding the location of each click to capture input.

Re: The war against autocomplete=off (2013)

#68

> Please note that if you combine this policy and at the same time disable copy and paste into the password fields (I look at you, Blizzard!), I hate you. oh man. disabling paste is the worst, because it breaks keypassx. (Apple did this last I checked!) turbotax did that as well last year, this year they made it sane again. Luckily there's a firefox about:config setting you can do to not let websites hijack / block y…

And Paypal! I closed my paypal account because of that

Re: The war against autocomplete=off (2013)

#69

My biggest problem is with sites that don't let me copy/paste into the password field. WTF!? Who's the PHB that came up with this policy? Despite this misguided nannying, I still use randomly generated 22 character alphanumeric passwords, even if I have to open up the window in Keepass and manually type them in. Most people aren't as paranoid and anal as me, however. Whoever you are, you're basically encouraging peop…

Equally bad: requiring a user to never use the same password twice

Come on, I only forgot my password and want to set it to what I think it should be! I didn't get hacked! Just let me live my life in peace!

Re: The war against autocomplete=off (2013)

#70
post #11

This drives some of our customers nuts because autocomplete has the annoying tendency in the most recent Safari of overwriting prepopulated fields - users end up losing configurations over this. Otherwise I can see the benefit of ignoring the setting, perhaps, but we need consistent default behavior (chance would be a fine thing!). I don't want to be telling my customers that they should switch off autocomplete as a…

Have you filed a bug report about Safari overwriting prepopulated fields? If not, and you don't want to deal with the painful experience that is bugreport.apple.com, feel free to drop me an email with more details about what you're seeing.
Post reply on HN