Live data from Hacker News

Safari tries to fill username

github.com

281–290 of 393 posts

Re: Safari tries to fill username

#281

Earlier quoted context omitted.

But should all sites really be optimized for the user at a public library computer? At the expense of convenience for the large majority of users that are on a personal or work computer? Doesn’t make much sense to me. Also the computer itself solves this problem for you in many cases, a guest profile typically deletes all browser session info when you log out.

All sites? Probably not. Many sites? Probably. You're assuming people log out reliably or otherwise behave in the most secure way. They don't. I also don't see how logging out/killing a session after 15 minutes of inactivity is much of a hardship for the user.

I hate _all_ sites that do this and I actively avoid them. There are many very good reasons why I might not be able to complete a form without interruption. It's not for them second guess me.

And it's not just extremely annoying, it's also completely unnecessary. Just put a "trust this browser" checkbox on the sign-in page and adjust the session timeout accordingly.

Re: Safari tries to fill username

#282
post #266

This is not really a Safari-only thing. All password managers that I have used in the past had some kind of heuristic to decide whether a field should be auto-filled or not. Here is a nice explanation by a (former?) 1Password employee ( https://1password.community/discussion/94198/autocomplete-of... ). To me as a web developer (among other things :D) this is quite annoying because password managers often hijack our f…

As well they should. I sometimes hate the password managers too as a web developer. I am also a 1Password user, and I hate sites that block clipboard, block pasting, block right click, basically block any kind of way I have to type even my username, not to mention annoying full size on screen keyboards that can only be used with the mouse. I don't care about the reason they have to be so intrusive in UX, probably som…

I have/wrote a one line auto hot key script for typing in strings in fields that don’t allow paste. Originally intended for a tax program that doesn’t allow pasting banking passwords. The pain of making a mistake and have to enter a 30+ character password over and over still haunts me.

Also, if you have a problem contact their customer support. I had a tweet get a few hundred likes about a non pastable field for a transportation website and they actually changed it later that week!

Re: Safari tries to fill username

#283

Earlier quoted context omitted.

>any credentials sent over HTTPS are transmitted in plain text Hummmm. So a couple of years back, I was working on some internal tools that passed sensitive information around and I found some interesting info. Some bloggers INCORRECTLY thought that HTTPS didn't secure the URL Flags. Correct fact: parameters passed in the URL like ?item=bla is encrypted Also, some cloud providers aload Balancers (AWS) allow you to of…

> Some bloggers INCORRECTLY thought that HTTPS didn't secure the URL Flags. Correct fact: parameters passed in the URL like ?item=bla is encrypted It’s still good practice to keep sensitive info out of URL query parameters, which often leak into server logs.

And are (were, maybe modern browsers fixed that by now?) sent in HTTP Referers to linked sites, end up in browser history, ...

Re: Safari tries to fill username

#284
post #261

Earlier quoted context omitted.

> Oh, and that password? Not case sensitive. What, you expect them to make a case-sensitive version of NTFS just to store your password??

NTFS is case-sensitive.

They made a case-insensitive version of NTFS just to store your password

Re: Safari tries to fill username

#285
post #201

Earlier quoted context omitted.

Doctors and lawyers are professions that are regulated by licensure, of which unauthorized practice comes with actual real and not made up legal consequences. Where is the similar licensure that tech security professionals are regulated by? I think that’s a big difference.

You may have missed the point being made. You find a good security professional the same way you find a good lawyer or doctor. Ask around for a reference for a good one. Then check their credentials (e.g., what certifications they have). I believe there was an article on HN recently about a startup that used a "lawyer" that wasn't because they didn't check their credentials after getting a great reference. Just becau…

You may have missed the point being made

I feel quite certain that I haven't, I just think the point is poorly made and I've spoken specifically to why I think that to be the case. You can get all the recommendations and referrals you want for an infosec professional; nothing stops that person from holding themselves out to be such a professional, quality of work or competency performing it notwithstanding.

You can absolutely suck as a pentester, but still legally hold yourself out to be one and advertise yourself as one to anyone who will hire you.

You can NOT do the same, holding yourself as an attorney or a doctor without very real risk of legal action if you are in fact-not licensed to do either. There are bar associations and medical boards governing various aspects of their work, and how their work is conducted, performs ethics and competency investigations on license holders, and can take away their license to continue working in such capacity if said investigations deem fit. No such governing board or ethical board exists for infosec professionals.

That is a pretty important difference that shouldn't be ignored just to make a petty point about how easy is is to ask for a referral.

Just because there are consequences doesn't mean it doesn't happen.

Which is only supplemental to all of this. My entire point is that it happens, and the prudent do the diligence to make sure it doesn't.

Re: Safari tries to fill username

#286

I don't see this as a bug. Password autocomplete is kind of a dumpster fire. It varies, depending on which sites I visit. I use 1Password, with browser integrations (it works better with Safari than Chrome). I don't know most of my passwords; relying on 1Password to access the strings of garbage I autogenerate. So I am constantly using it to fill forms. It keys on things like attached ... elements. Not all sites use…

I use BitWarden and have come to prefer something about BitWarden that initially irked me coming from LastPass. There is no icon in any of the fields to click to populate them. There is no auto filling. You have to cursor into the field, right click and manually select the relevant entry to fill. From a security standpoint this is much better and safer overall. It also prevents accidental autofilling and login of an…

Auto-filling on page load in Bitwarden is an opt-in feature.

Additionally, if you have Bitwarden in your toolbar, you can click the Bitwarden icon, then click the entry for the site, and it will auto-fill in the page for you.

I'm surprised anyone uses context menus to do this, though I agree with you that it's probably safer.

Re: Safari tries to fill username

#287
post #228

Earlier quoted context omitted.

This is the continued dilution of security with audit/compliance. It's a mindless, check the box mentality. They don't care about real-world security, they offer insurance to cover the losses. But many insurers are no longer paying due to the volume of incidents and the lack of sound security. The auditors are typically 10 to 15 years behind technical security expertise.

> This is the continued dilution of security with audit/compliance. It's a mindless, check the box mentality. If I can play devil's advocate for a moment—isn't this just how insurance necessarily works? Your car insurance company isn't going to interview your teenage son; they don't care that he's a particularly mindful individual, who never speeds because he remembers the time a close friend died in a car crash. "Th…

Bad example. They aren't going to interview your son, but _most_ will take his high GPA and certificate of completion of Driver's Education class, and give you a discount for it, which is the next best thing without spending the time to interview him.

Re: Safari tries to fill username

#288
post #287

Earlier quoted context omitted.

> This is the continued dilution of security with audit/compliance. It's a mindless, check the box mentality. If I can play devil's advocate for a moment—isn't this just how insurance necessarily works? Your car insurance company isn't going to interview your teenage son; they don't care that he's a particularly mindful individual, who never speeds because he remembers the time a close friend died in a car crash. "Th…

Bad example. They aren't going to interview your son, but _most_ will take his high GPA and certificate of completion of Driver's Education class, and give you a discount for it, which is the next best thing without spending the time to interview him.

But isn't that driver's education class certificate basically a “checkbox”? I don’t think it’s so different from those IT certifications.

Re: Safari tries to fill username

#289
post #226

Earlier quoted context omitted.

this x 10, computer security is usually flawed, personal security is (bar a few war zones) much better.

there are a lot of war zones in this world though. given that and the number of Third World countries with high levels of crime and poor public security, I suspect that a significant percentage of the worlds technology-using population might have better digital security than physical security

It's always about evaluating your OPsec and tailoring it to your needs and threat assesment.

Re: Safari tries to fill username

#290
post #179
post #173

Earlier quoted context omitted.

I do not. Ultimately it is up to the website owners, it shouldn’t be ignored by the browser if it’s part of the spec.

Why do you think it is up to website owners, and not website users?

You can strengthen that... it is up to the users, as a matter of practical fact. I've right-clicked -> edit attribute -> autocomplete=true more than once. I've cleared the right-click handlers and keypress handlers that were blocking paste, or run $0.setAttribute("value", "paste your password here on the console where they can't stop you") (after you select the element in the inspector).

Browsers as they stand now are not capable of truly blocking autocomplete, or pasting into a field with an input box. If they aren't implementing their own text field with a canvas and taking keystrokes themselves they aren't blocking paste anyhow. (And if they do that I can still tampermonkey or something my way into a "paste".)

Post reply on HN