The war against autocomplete=off (2013)
61–70 of 78 posts
Re: The war against autocomplete=off (2013)
#62Earlier quoted context omitted.
Compared to weak passwords, phishing and a myriad other threats, how likely is that someone will walk up to my computer and copy a password? How likely are they to have a true criminal intent rather than a prank on their mind? And when your machine is compromised or otherwise controlled by an untrustworthy third party, you lost anyway.
Nobody is arguing that autocomplete is a threat on par with phishing.
So, for most people you trade a near meaningless threat to fight a major one which tends to be a net win.
Re: The war against autocomplete=off (2013)
#63Re: The war against autocomplete=off (2013)
#64The original article fails to take into account the larger population. The basic password managers in browsers are huge security holes. The one in FF does not use a master password by default, so anyone could look at an unattended computer and see all stored passwords with a few clicks. The article mentions an old JavaScript attack on the passwords as well (but then dismisses the threat, since that one hole was patch…
No, what happens is that autocomplete=off flag is a flag to make sure you are using your brain as a password manager, which experience has shown to be a terrible idea.
Instead of a browser password manager that can help make your passwords unique per site and comprised of random characters, users are forced to use passwords from their head, likely sharing them between sites. Someone coming to your unattended computer isn't nearly the threat of you using a simple and short password across every site you visit, including the sites that end up with a stolen passwords database or have a moronic password recovery option.
Re: The war against autocomplete=off (2013)
#65I've run into the problem of web services not letting me store passwords. The reality is, if you let my password manager (safari jacks into OS X's keychain system) keep track of things, I'm going to use the random 12-digit alphanumeric password my password manager provides me. If you don't, I'm either going to use my shitty "brain" password or put it in my password manager anyway and just copy-paste it manually. Than…
Re: The war against autocomplete=off (2013)
#66Someone was showing me Capital One 360 (formerly ING), which uses an onscreen PIN pad that you either have to click with your mouse, or type using a randomly generated mapping. The idea is to thwart keystroke loggers, but it's totally infuriating.
Re: The war against autocomplete=off (2013)
#67https://addons.mozilla.org/en-US/firefox/addon/remember-pass...
It's heavenly.
Re: The war against autocomplete=off (2013)
#68> Please note that if you combine this policy and at the same time disable copy and paste into the password fields (I look at you, Blizzard!), I hate you. oh man. disabling paste is the worst, because it breaks keypassx. (Apple did this last I checked!) turbotax did that as well last year, this year they made it sane again. Luckily there's a firefox about:config setting you can do to not let websites hijack / block y…
Re: The war against autocomplete=off (2013)
#69My biggest problem is with sites that don't let me copy/paste into the password field. WTF!? Who's the PHB that came up with this policy? Despite this misguided nannying, I still use randomly generated 22 character alphanumeric passwords, even if I have to open up the window in Keepass and manually type them in. Most people aren't as paranoid and anal as me, however. Whoever you are, you're basically encouraging peop…
Come on, I only forgot my password and want to set it to what I think it should be! I didn't get hacked! Just let me live my life in peace!
Re: The war against autocomplete=off (2013)
#70This drives some of our customers nuts because autocomplete has the annoying tendency in the most recent Safari of overwriting prepopulated fields - users end up losing configurations over this. Otherwise I can see the benefit of ignoring the setting, perhaps, but we need consistent default behavior (chance would be a fine thing!). I don't want to be telling my customers that they should switch off autocomplete as a…