Live data from Hacker News

Issue 914451: Autofill does not respect autocomplete="off"

bugs.chromium.org

331–340 of 383 posts

Re: Issue 914451: Autofill does not respect autocomplete="off"

#331

Earlier quoted context omitted.

What is the compromise? What is insecure about me being me? Either we talk past each other not understanding each other's point, or I feel like you profoundly misunderstand the reason for people using username/password for authentication nowadays? With most things you need to authenticate to gain access. Authentication is only trying to solve one question - identifying that a person is who they say they are. If I wal…

A biometric identifies you. An identity does not inherently authenticate you. Identification is knowing which account to log in. dustinmoris, User123 or user124. That alone is useless, as anyone who knows your name could log in. So we need to add security to authenticate you. To authenticate with reasonable certainty that the person accessing dustinmoris actually is Dustin Moris, at this moment willingly accessing th…

You highlight flaws in faceid, etc but passwords also have flaws.

- Fingerprints can be lifted from pictures. - Passwords can be forgotten and thus have seriously flawed reset schemes that often fallback to something as simple as having the right phone or backup code. - passwords can be lifted by keyloggers - passwords can easily be phished - passwords can be shared

Authenticating access can come from 1 or more of: something you know, something you have, something you are.

They each have flaws. They all do the same thing.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#332
post #25

Earlier quoted context omitted.

>Are people doing this just to annoy users who prefer password managers? People are doing it because they don't understand password managers, and think blocking them makes people more secure. They believe that if a password is in a manager, that password is less secure than if that password was purely in the user's head.

If a bug in the password manager leaked the password to your bank to a third party, many users wouldn't want to pay for any associated costs/expenses when a bad guy steals their money. Yet the bank also doesn't want to take on security audits for code entirely outside their control.

Then banks should recommend a good password manager. It's on them to make their users happy after all.

One part of that is a proper risk analysis. Password reuse and weak passwords are much bigger risks than a rouge autocompleter.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#333
Or line of business applications which (when rendered with Chrome) wants me to pick from my credit cards when I enter a certain field which has nothing to do with credit cards. I think it depends on the field name, but there seems to be a very loose correlation.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#334
post #180

Earlier quoted context omitted.

I agree - and in fact, I think accusing this guy of being rogue is an unnecessary direct attack on him/her. They are just doing their job, and in this case, acting in what they believe is best way for users. Here on HN, it seems most disagree, but that is still no reason to accuse someone of being rogue. Headline should be "Google Chrome actively ignores HTML5 standard"

The standard says "SHOULD", not "MUST". (Disclosure: I work for Google)

SHOULD means you can ignore it in particular circumstances and with good reasons. Not all the time as a matter of UI judgment.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#335
post #104

Earlier quoted context omitted.

The spec only says "should", not "must". Apparently these wingnuts thought that means the spec can be ignored.

> The spec only says "should", not "must". Apparently these wingnuts thought that means the spec can be ignored. Not arguing in favor of this particular choice, but yes. That is exactly what "should" means in most cases. For instance, in RFC 2119: https://tools.ietf.org/html/rfc2119 > SHOULD This word, or the adjective " RECOMMENDED ", mean that there may exist valid reasons in particular circumstances to ignore a pa…

Blanket disregard of a SHOULD directive as a UX decision neither falls under "in particular circumstances" nor indicates that they've "understood and carefully weighed" the consequences.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#336

A few years ago, I left a $1000 tip at the restaurant up the street because Chrome filled out the tip field with my zip code (which thankfully merely defaulted to max $1000 instead). The tip field was off-screen, and the ordering software didn't have a confirmation screen, just a "we just charged your card $X amount" screen, which made my eyes boggle. EDIT: Looking at the original March 17th, 2015 bug, it would have…

The tip field was off-screen

I wonder how much the [1] hiding of scrollbars and [2] UIs with excessive amounts of whitespace, increasing the need to scroll also contributed to you making this error.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#337

This has turned into a sad chicken-race between Google and developers, with lots of innovative workarounds on Stackoverflow. Their tactic of overruling web developers doesn't work, it only make things more complicated for everyone, since many of the workarounds have other negative side-effects. https://stackoverflow.com/questions/12374442/chrome-ignores-... ## Example 1 For a reliable workaround, you can add this cod…

> “ This has turned into a sad chicken-race...”

great dash use! i almost read that as a race of sad chickens (seriously) but the dash autocorrected me. bravo!

Re: Issue 914451: Autofill does not respect autocomplete="off"

#338
post #226

Earlier quoted context omitted.

When a phrase is used the “wrong” way more often than the right way, it ceases to be wrong.

Idiocracy, defined.

“Idiocracy” doesn’t appear in my dictionary, how did you come to know what it means?

Re: Issue 914451: Autofill does not respect autocomplete="off"

#339

Earlier quoted context omitted.

>I can tell you that the higher management at Google does not dictate chromium changes as they are too technical for them. Tell that to the webRequest API that ablockers use. >As you said for the exceptions, Microsoft can maintain a fork, it's still order of magnitude more economic and smart than to constantly duplicate work in a redundant browser (firefox) Chrome is the redundant browser. Firefox was here first.

webRequest API Well maybe it's an exception, but they have technical reasons mostly. Webrequest v3 is not stable so wait and see. Chrome is the redundant browser. Firefox was here first. Well Chrome is based on khtml which is not that new but yeah Netscape navigator precede it. Indeed it would have been better if chrome was based on gecko (FF) at the time. But now Firefox can be thought of the redundant browser becau…

> webRequest API Well maybe it's an exception, but they have technical reasons mostly. Webrequest v3 is not stable so wait and see.

Bullshit. They decided they wanted this to fuck with adblockers, then found some "technical reasons" they could use as talking points, afterwards. Also, the reasons are apparently so "technical" and "necessary" that google said it would not apply the proposed crippling of webRequest to corporate deployments of Chrome. Corporate users apparently do not need privacy or performance. Go figure.

"B-but user privacy! Extensions can see request" - This is grand coming from google in the first place. Nonetheless, an easy way to solve this is to have special "webrequest" scripts which can apply rules etc, but cannot communicate out, so cannot exfiltrate data.

"B-but performance" - Wasn't a problem so far. If you're really concerned about those 10ms per request an adblocker might add, then either don't run one (and see how your "perf" behaves when all those nice ads load instead), or run one that uses the declarative stuff, which google can still implement additionally.

>If mozilla worked on improving chromium, think of the massive progress it would bring to the World! Website would have no limits on what is possible to create. Everything would be fast, etc.

By "massive progress" you mean outright monopoly on the internet technology for Google? That's not progress. I'm still mad at MS. Instead of taking google's sabotage (you cannot call it anything else really), they shouldn't just obeyed the new goverloads, but sued the living shit out of google. I bet they now a few good antitrust lawyers.

Re: Issue 914451: Autofill does not respect autocomplete="off"

#340
post #94
post #82

Earlier quoted context omitted.

Imo, valid use case for autocomplete=off is "the developer of webapp wants it". Literally that and nothing more.

It's called "user agent", not "developer's agent". We'd be in a terrible situation if the browsers just followed developer's whims. Cf. popup blocking.

And e.g. disabling Paste. But it seems clear that autocomplete gets it wrong often enough that developers should have some say in the matter.
Post reply on HN