Re: [whatwg] Password managers ignoring autocomplete='off' harming security

On Wed, Oct 1, 2014 at 4:34 PM, Gavin Sharp <> wrote:

> That browsers now automatically go fill in sensitive data (passwords)
> into these password fields is the issue, because people might not
> notice that happening and then submit the form.

OK, but how does that cycle get started?  I could be wrong, but I believe
in Chrome that we won't autofill your password from site X into a password
field on unrelated site Y.  You have to have explicitly used that password
on site Y to fill it in the future.  So if people are getting sensitive
data, that was never supposed to be in these fields to begin with, filled
into the fields, how is that happening?  Are browsers being aggressive
about attempting to fill data from one site into another?  Does this happen
across browsers?


Received on Thursday, 2 October 2014 00:25:21 UTC