RE: Risks the password role does create



From: Richard Schwerdtfeger [mailto:richschwer@gmail.com]
Sent: Wednesday, June 22, 2016 1:58 PM

The first bullet is a new one I had not seen. However, the same bots can search for the label “password” on input fields and do the same thing. There is nothing new here.
[Jason] I agree. At best it’s marginally easier (matching the role would help the attacker to circumvent internationalization issues).
As to the other point, I somewhat doubt the effectiveness of ARIA in influencing authors’ decisions regarding when to create custom widgets I further agree that the remaining issues are problems with custom password fields generally and would be unaffected by the availability or otherwise of the ARIA role. Thus I do not support the objections to this feature.


________________________________

This e-mail and any files transmitted with it may contain privileged or confidential information. It is solely for use by the individual for whom it is intended, even if addressed incorrectly. If you received this e-mail in error, please notify the sender; do not disclose, copy, distribute, or take any action in reliance on the contents of this information; and delete it from your system. Any other use of this e-mail is prohibited.


Thank you for your compliance.

________________________________

Received on Wednesday, 22 June 2016 18:07:29 UTC