Autofill abuse allows websites to grab sensitive userdata
board.protecus.de
board.protecus.de
[1] - I know obfuscation is minification meant for minimizing bandwith consumption. It's still obfuscated code, despite best intent.
[2] - I understand that the code execution is sandboxed inside the web browser, but really is it at all possible that, you know, these guys let the occasional security flaw slip?
Eye candy is great, but Javascript has often been a vector for privacy issues. Hence the popularity of Noscript and most browsers having an option to disable Javascript.
No, every user of NoScript sees it. At the end of the day, your computer has executed billions upon billions of instructions, most of which you have no idea what their purpose is or if they leak your security or privacy. Even those of us running a Linux box have this problem. I trust a lot of code, I trust my CPU and my BIOS and my OS, and my NoScript whitelist has only grown, it doesn't shrink. (It does gain temporary permissions every so often when I don't quite trust the source but figure the risks are negligible.)
The vast majority of people (and website owners) don't want to harm you or your computer or society as a whole (There is a lot of low-hanging fruit for the studious domestic terrorist.) People have good reason to think they'll be safe executing unknown code. The model caught on because it's useful and because the web of trust extends far. NoScript is still used by the minority and that's unlikely to change.
To truly fix this bug, though, it would be nice to also stop autofill of technically "visible" fields that are tiny or under another object or otherwise obscured. But that might be orders of magnitude more difficult.
If I enter my real name somewhere, I'm probably fine with providing my phone and post address, too. When in doubt I use a fake identity.
what about chrome's credit card autofill?
Aye. But when I enter my email adress somewhere, I don't necessarily feel comfortable giving them my real name + phone number
The fun thing about this type of vulnerability is if you know the user's name, you can build an invisible form component to get the browser to spill the stored password.