> This is not a security vulnerability itself because I think they have implemented this for some reason IMO just because the behavior is by design doesn't mean it's not a vulnerability. That said, this one seems like a grey area. I'd be worried about password information leaking by making TLS attacks easier in this mode.
This only affects a specific form that the user might interact with once a year (and that's being really optimistic), I don't really see it generating enough requests to make TLS attacks easier.
I think the real point here is that there are more secure solutions. Saying that it's not all that less secure isn't a great argument.