I think it means that sites can't overrule the browser's inclination to store passwords. The argument seems to be the browser makers will store passwords safely.
Not quite. Unless you set a master password, whoever owns your computer will own the passwords stored by your browser.
The argument is that disabling autocomplete makes users choose poor passwords that are easy to remember, or write passwords down somewhere, which is at least as bad as having passwords stored in your browser profile.
If anyone has that issue, a workaround is to add multiple email/password inputs (dummies) around the real-one, and hide them. In Chrome, this causes it to 'give up' and not try to auto-fill the fields.
Summary of the change, so people don't have to wade through a long discussion:
- This change makes it so that `autocomplete=off` does not stop the Password Manager from working. Normal form autofill can be disabled as usual.
- The password manager *always* prompts if it wants to save a password. Passwords are not saved without permission from the user.
- We are the third browser to implement this change, after IE and Chrome.
- This can be undone locally by flipping the `signon.storeWhenAutocompleteOff` pref (from about:config) off.
- The rationale behind this change was the widespread abuse of the `autocomplete` attribute to prevent password saving where no prevention is required. This change gives users full control over password saving, without compromising on security (again, the user is always prompted).