Chrome does not respect autocomplete=off (2018)
bugs.chromium.org
bugs.chromium.org
All browsers right now basically assume that if you have an input type="password", then the previous input type="text" must be the username field. And there's little you can do to change this without resorting to substantial hacks like using a hidden username-looking honeypot field to eat the poor browser behavior.
For example, imagine a pop-up confirmation box that asks you for your password before continuing. Or really just a "confirm password" field on any form. It can be very hard to get browser or extension password autofill to only affect that one field and not inject a username into some other field on the page. Password managers in browsers and extensions are surprisingly brain-dead, and they give us no tools to help them out.
To put UX first, especially around something as UX-sensitive as password autofill, you end up needing to put in a lot of extra work to make up for the browser's confidently-wrong implementations.
The original decision to ignore autocomplete="off" was probably the right move. But now that the autocomplete attribute has been overloaded with password manager concerns built in to web browsers these days, nobody has bothered to revisit the ordeal.
autocomplete="current-password"
autocomplete=off should just be removed and it be entirely up to the user-agent whether it gets used like reader mode.
I think these features should be like the notifications pop-ups “This site requested that Chrome not automatically fill out forms. Tap here to enable autofill anyway for this site.”
Giving the user more control is great: things like reader mode, option to disable auto-play video or options to kill resource-intensive scripts. This isn't a tool for the user, it is the browser's behavior whether the user wants it or not.
If autocomplete=off is user-hostile, then it should be changed in the spec. The spec gives a few use cases (site has its own autocomplete, field is sensitive information that shouldn't be cached, field is a one-time key). If autocomplete=off is removed, how would those cases be handled?
https://html.spec.whatwg.org/multipage/form-control-infrastr...
Chrome decided to add autocomplete to some of our fields with contextually irrelevant options. As far as I know there isn't anything I can reliably do about it.
Am I missing something? Is there some sort of heuristic to when it actually disables that I just got on the good side of by pure luck?
Yep, you are.
Chrome will fill in fields by not just looking at the autocomplete attribute, but also by trying to magically infer it based off the name attribute (and other heuristics).
For example, if you have a text entry box for a filename, and happen to set "name='name'" on it, even with autocomplete off you will get a pick list of people's names.
https://developers.google.com/web/fundamentals/design-and-ux...
Like are you kidding me? I went into my bank app/website, I used the "copy" feature, and I'm trying to paste here AND into your "confirmation" field. Because I don't want to typo it!
How could my copy skill be worse than my typing skill?
In practice as a developer you have to resort to JavaScript hacks and obfuscating form field names to avoid it.
I figure most people just tolerate wrong inputs and live with the results. (It doesn't happen that often.)
> It's very hackish way but I found a trick to achieve the same.
> So you should go to chrome://settings/addresses?search=address
> Now create multiple addresses, each with only one field filled. So one should only have your E-Mail, another record should contain only your first name only, and so on.
https://superuser.com/questions/477144/can-autofill-in-chrom...
A variation:
The PCI-DSS council is partly to blame here, for recommending autocomplete=off in other contexts.
At least I could imagine this prop being applied to hidden elements, either in pfSense or internally in chrome.
It may well be that disabling autocomplete is open to abuse, but it's not up to the browser venders to police the quality of webpages. There are plenty of other features that are abused all the time. Should browsers disable window.onscroll because it can be misused? How about all of JavaScript?
But I've also been bitten by autocomplete bugs. It has a strong tendency to make the user do the wrong thing and then forces developers to use silly hacks to stop it. It's not as bad as the IE6 days, but it's not ammillion miles away.
The problem was even more frustrating because it seemed like disabling it was the only workaround to prevent a strange mobile Safari issue where the autocomplete bar would push the "next/prev element - Done" bar, on top of the keyboard, up so it would overlap the "position: fixed; bottom: 0;" element on the page (which was the input the user was trying to write into).
The argument that the user would complain to the browser vendor if he couldn't autocomplete is a bit strange to me. I would think the real novice users would begrudgingly accept the inconsistent behaviour and the users that do care about it would complain to the website they were on. But then again I haven't read any user studies regarding this.
I have the password manager disabled (supposedly) and using 1Password, but Chrome's version still pops up on login forms and interferes with 1Password.
No developers seem to have a problem simply refusing to support Firefox. I wonder how much extra effort it is going to take for them to finally make the switch.
This statistic is not without reason. Chrome still has considerable usability and security advantages, especially for non-technical people(at least on anything that's not OS X), and still the best dev tools out there.
We can be lucky that FF at least tries to stick to standards where Safari doesn't bother.
As long as the corporate/enterprise apps work on Firefox (which they should?), it's not a problem for a corporate IT department to ban Chrome.
They have even less of a reason to support Firefox. I used to work on an partially enterprise (well, government) program. We dropped Firefox support for it because it was easier to tell the client to just install Chrome. And the complexity of enterprise software means that that will always be easier for the client as well than switching.
I don't think any IT department worth their while would ban worthwhile software because of some agenda that frankly just doesn't matter too much to most regular users, at least in an US context.
In the EU this might be a bit different, as they would have an interest in getting Google out of their ecosystems - but we've seen that that just doesn't really work too well, with pilots in various governments. People aren't as productive and complain about not having the same Excel and the same Internet as they have at home.
For the longest time Chrome would search google first before local DNS for FQDNs. When I reported that years ago they labelled it "wontfix."
In Chrome 69 they started single-sign-on and didn't get around to adding an option to disable until 71. And this autocomplete bug has been a problem for years also.
There are valid reasons to switch. I'm not here to make users feel at home. I'm here to make sure the stack runs on their machine. I find that is easier to accomplish with Firefox.
This shows a disconnect / bubble. Lots of IT departments require permission to install any software, i.e., a whitelist, rather than the blacklist being proposed (and which is fine in this instance). Granted, many of those places don't care about their employees being as productive as possible (even if they tell themselves they do), and their IT departments aren't worth their salt, and this tends to be norm, unfortunately.
wat. Developer gag left unchecked?
Unfortunately, in reality, it's probably more often used to force users to type things in for misguided "security reasons".
I think browser UI for this is generally just bad. I think forms should never auto-fill, but when I click on a form field, it should give me a dropdown to select text to put in just that field. Not that field plus all other fields in the form. Just that field. Then you don't have privacy issues (because the site never sees the autocomplete options unless the user actively selects one), and autocomplete="off" becomes unnecessary.
https://stackoverflow.com/questions/15738259/disabling-chrom...