22 ms·
> they made all top-level event listeners passive by default. They call it “an intervention”. This is my very problem with Chrome/Chromium right now. The Chrom
by KeitIG 9y ago
> they made all top-level event listeners passive by default. They call it “an intervention”.
This is my very problem with Chrome/Chromium right now. The Chrome team does assumption on how things "should" be (in a highly subjective way) and breaks the web.
Another example: they decided to ignore the value of `autocomplete` attributes on `<form>` tags [1], because:
> The tricky part here is that somewhere along the journey of the web autocomplete=off become a default for many form fields, without any real thought being given as to whether or not that was good for users. This doesn't mean there aren't very valid cases where you don't want the browser autofilling data (e.g. on CRM systems), but by and large, we see those as the minority cases. And as a result, we started ignoring autocomplete=off for Chrome Autofill data.
Problem: Chrome now auto-fills wrong parts of forms with username/passwords and this breaks forms that get unexpected data when submitted. And now, they opened an issue on their tracker [2] to track "Valid use cases for autocomplete=off".
This is insane to think that the developer is wrong to use some attributes values, and to assume how a page should behave, ignoring devs intentions and Web standards.
[1] https://bugs.chromium.org/p/chromium/issues/detail?id=468153#c164 https://bugs.chromium.org/p/chromium/issues/detail?id=468153...
[2] https://bugs.chromium.org/p/chromium/issues/detail?id=587466 https://bugs.chromium.org/p/chromium/issues/detail?id=587466
- hinkley 9y agoThis is just arrogance. From a historical perspective, this is nowhere near the sort of behavior one saw from Microsoft in the 90’s, but that’s pretty faint praise - nobody wants anything like that to happen again. You shouldn’t have people contributing to competing products out of spite. I hope we never hit the point again where it is a cliche for FOSS people to bond over shared hatred of a company. I’d like to think we have been inoculated against that. I like to see people who will speak up like this early and often.
- drewmol 9y agoAs I've seen others mention, there seems to be a divide between the most user friendly behavior for: (1) public webpage w wide ranging user base that will be consistently updated and developed+ monitored for the widest compatibility, latest security, and (2) the CRM, intranet app, hardware config portal, etc. that will not. Any web devs have recommendations on how they handle the two circumstances?
- wmeredith 9y agoI am the Director of UX for a CRM SaaS product. The ignoring of web standards (like autocomplete flags) is misguided and totally obnoxious. Chrome is terrible about stuff like this. It drives me crazy.
- xupybd 9y ago>This is my very problem with Chrome/Chromium right now. The Chrome team does assumption on how things "should" be (in a highly subjective way) and breaks the web. And that is how IE used to operate. I think this is something we're going to have to deal with for a long time.
- Benjamin_Dobell 9y agoChrome also recently broke sendBeacon functionality in a rather unusual fashion. The API is documented to return false if it fails, but apparently it'd be way more hilarious if instead of returning false as documented, Chrome just started throwing exceptions... Oh, and the reason for the exception, a bug in Chrome's security, that will be resolved at a later date. https://bugs.chromium.org/p/chromium/issues/detail?id=490015 https://bugs.chromium.org/p/chromium/issues/detail?id=490015
- Benjamin_Dobell 9y agoAnd another one... https://bugs.chromium.org/p/chromium/issues/detail?id=696126 https://bugs.chromium.org/p/chromium/issues/detail?id=696126 Broken WebGL anti-aliasing because: > for now since it _shouldn't_ affect any actual devices Except well... it did.
- hackerfromthefu 9y agoAnd, unless this has been fixed (does anybody know?) .. Autocomplete is a security problem that can be used to get more information from users than they think they are providing - just ask for one field like email but put the other fields to be auto completed as hidden, and the browser helpfully gives the site all the other fields the user didn't realise are being autocompleted..
- pg_is_a_butt 9y agobut but but, that one guy said that women were different. you're all idiots. you deserve this. you deserve worse.
- mad182 9y agoAs a user I think ignoring autocomplete="off" is great decision. More often than not it's misused and annoying. As a developer, I have never used it anyway, so don't care.
- wiredfool 9y agoI believe autocomplet='sudo_off' works now, or at least, it puts the field into a different set of autocomplete that isn't triggered by default.
- bad_user 9y agoThey can afford to do this due to their market share. This is precisely why I refuse to use Chrome. I use Firefox and would do so even if it were an inferior browser, plus at this point in time and for my usage patterns Firefox really is superior.
- nevir 9y agoFirefox (and IE) did the same thing for autocomplete=off, with the same rationale. https://bugzilla.mozilla.org/show_bug.cgi?id=956906 https://bugzilla.mozilla.org/show_bug.cgi?id=956906
- chimeracoder 9y agoTo be clear, it appears that Chrome disables autocomplete=off for all fields and forms, not just for password fields. The linked ticket is about password fields in Firefox specifically.
- ckocagil 9y agoYou're refusing to use Chrome because it gives the middle finger to websites that want to disable your password manager? Are you making this decision as a user or a website owner?
- noxecanexx 9y agoChrome disables it for all fields. That's the difference
- LoSboccacc 9y agothat change in particular broke most of two factor authenticated bank pages X:
- andybak 9y agoIsn't this a reaction to moronic use of autocomplete=off in a user-hostile way by various websites? In a similar vein to how abuses of disabling the back button, popups etc have led to defensive measures by browser vendors.
- Bartweiss 9y agoSort of? Autocomplete=off is abused, certainly. It's commonly used to interrupt password manager functionality, in much the same way that copy/paste disabling is used on "repeat new password" fields. (As an aside: disabling autocomplete is a good idea, but only on the password manager level, not the website level. It's defense for user privacy, so employing it on well-meaning websites is worthless.) But it's not abused in the user-endangering manner that circular redirects and back button hijacking have been. (Specifically, to make scam sites hard to escape and easy to click into.) It's just an inconvenience to users, and honestly I'm not thrilled to see browsers override code for non-security reasons.
- KeitIG 9y agoYou are right, but my personal problem here is autocomplete is automatically applied where it should not be. [1] [1] https://bugs.chromium.org/p/chromium/issues/detail?id=587466#c83 https://bugs.chromium.org/p/chromium/issues/detail?id=587466...
- akvadrako 9y agoThere is no general solution; only the end-user is smart enough to know when autocomplete should be used, and asking them to specify it for every field is too much work. Personally, I installed a Safari plugin to ignore autocomplete=off because it was so annoying. So Chrome is doing what I want my browser to do.
- WorldMaker 9y agoThat's just it, maybe it is time to put it back into the hands of the end-user? You don't need to ask the user for every field, just an override for fields that have autocomplete=off. Add a simple mark for "Autocomplete was turned off on this site for this field" where clicking it overrides. You could add similar marks for fields with onpaste handlers to deactivate them.
- Spivak 9y agoThe problem is that some sites decided to use autocomplete=off to impose their feeling about password managers on users and make them more difficult to use. It's the same reason I have to turn off clipboard events because some sites think it's okay to block copy/paste.
- hbbio 9y agoPassword managers use browsers plugins, and as such can modify pages before they render as much as they like.
- pluma 9y agoHow is this different from websites that think it's okay to force you to abide by ridiculous password restrictions (e.g. 6-8 characters, must include digits, upper- and lowercase letters, and special characters but no quotation marks or any known SQL keywords)? The right thing to do is to bring the issue up with whoever is running the website. If they decide not to act on it because they think they know security/UX better than Google/you, they're stuck with crappier security/UX and the market should sort it out. I've actually managed to convince a company to stop prohibiting copy-paste on logins by pointing them at the new NIST password guidelines. I don't expect this to work for every company, but if they intentionally don't change, it's okay to name and shame them for it. Whether it's a UX sin or security voodoo.
- Arzh 9y agoPersonally I have found I was more annoyed with forms not allowing me to autofill before the change than times I have seem chrome fill the wrong fields out after.
- deleted 9y ago[deleted]
- saas_co_de 9y ago> does assumption on how things "should" be (in a highly subjective way) They claim they are making these decisions based on user data which I have no reason to doubt. > and breaks the web. Breaks crap websites that are broken already from performance and usability perspective. I personally think this is exactly what is needed to make the web better as a whole. Individual developers working for individual companies are rarely if ever thinking about the good of their users, except in a very narrow profit motivated sense, and never thinking about the good of the ecosystem as a whole. Google is also "breaking the web" by not auto playing videos, not allowing alerts in one tab to block the entire browser, etc. Those all seem like good things to me.
- twothamendment 9y agoHow about deciding to ignore requests to play a sound? I like it as a user but as a dev, now I have a big report that says the cash register isn't making a beep sounds when the user scans an item. Yes there is a setting to turn it off, but now there are quite a few people confused about why it quit working.
- FussyZeus 9y agoSo aside of the fact that you agree with their decisions, how is this at all different from how Internet Explorer's dev team made arbitrary decisions on how things would work in their browser, and in so doing because of their market dominance, influenced how the web grew, looked and functioned for decades to come? And how much technical debt had to be tacked onto every project to address that need (and is to this day)? I'm all for moving the web forward and addressing stuff like this is a critical part of that, but this is not moving the web forward, this is moving Chrome forward, and in so doing breaking thousands if not millions of sites, and placing the burden of their repair on their developers with no notice and no better solution, just a different hack than the hack they were using.
- CydeWeys 9y agoThere are several other first-class browsers that you have a choice of if you don't like Chrome. The same was not true during IE's era of dominance. Also, do you agree, in general terms, that sometimes changes can be good whereas other times changes can be bad?
- dhimes 9y agoThey've also done something so threatening to users' security that I can't take them seriously on the issue. They've been doing it for years, they refuse to change, and it makes me conclude that they fundamentally don't understand the problem. Every update of chrome erases their password manager entries. So for every site their password has to be re-entered. Why is that dangerous? Because that means that my cousins and nephews other regular folks cannot trust Chrome to keep their passwords, so they must either reuse passwords or write them down somewhere. Obviously, a third-party password manager is simply not an option for these folks- they rely on the browser. The browser can get it right or get it wrong. Chrome gets it wrong.
- emodendroket 9y ago> Every update of chrome erases their password manager entries. That has not been my experience.
- dhimes 9y agoI wonder what the difference is? It's been going on for years. https://superuser.com/questions/926902/google-chrome-loses-does-not-show-stored-password-after-an-upgrade https://superuser.com/questions/926902/google-chrome-loses-d...
- emodendroket 9y agoHave they enabled the Cloud password sync thing?
- dhimes 9y agoThey may have but I don't use it.
- emodendroket 9y agoI use it and my passwords stick around, so perhaps enabling it would help?
- artursapek 9y agoI had a form on the website I administer that closes a user's account permanently. It requires them to input their password and click a button (with a confirmation dialog). Chrome was seeing that password input and auto-filling it, making it very easy for a user to accidentally close their account. It did the same thing for a "change username" form, which also had a password field to confirm the change. Chrome thought it was a login form and would pre-populate the "new username" field with the user's existing username. I tried so hard to make Chrome not do that.
- jhasse 9y agoJust put a captcha on the user deletion page: problem solved.
- bluetwo 9y agoI haven't run into this issue but the autocomplete=off thing annoys the cr@p out of me. If you have a simple web app that has an administrator mode for editing accounts, you should be able to turn off autocomplete so your password doesn't automatically get filled in for users that you edit. It's that simple.
- leeoniya 9y agothis is such an obvious use case, they basically threw a ton of web-apps/crms under the bus.
- jimktrains2 9y agoWhile I dislike this behavior of chrome, you should never be able to set a users password.
- leeoniya 9y agoi dunno why you're getting downvoted. you're right about this. but this doesn't apply to autofill behavior of non-password fields.
- bluetwo 9y agoIt is arrogant to assume this is true of every single use case.
- jimktrains2 9y agoI really can't think of a scenario where the end-user not being in full control of their credentials is good. Are there situations in which it is easier if the admin can just reset it, sure. Is that a good idea, no.
- bluetwo 9y agoYour mistake is thinking a login is a person and a person has an email. I have run into all three of these scenarios: 1) A login for an administrator area on a server has a different login/password than the main area, and the browser always fills in the main login/password, even though I ask it not to. autocomplete=off would fix this. 2) A new user and edit user screens exist in web apps that are driven by users sign-ups. Sometimes these things need to be coordinated with other systems in a corporation and users do not always have their own email (I know this is a shock for you, but it is very common). autocomplete=off would fix this. 3) Using a remote admin tool to setup a datasource on a server, the username and password fields refer to database credentials, not a person. Yet Chrome keeps filling in my info. autocomplete=off would fix this.
- tomjen3 9y agoI am going to have to disagree there - I think putting autocomplete control in the standard was an error, just as a webdev shouldn't be able to not accept copy and paste. That is inherently a user choice.
- agentultra 9y agoRegulatory compliance. I've worked on applications that had to go to great lengths to get the target browser platform to not do something like auto-complete authentication credentials. Philosophically-speaking some Web Platform developers think that it's more secure for the browser to autofill credentials from a keychain so that users can use better passwords and not be burdened with remember N-pseudo-random character sequences. Sounds good. Probably is good. Whether or not you agree with the above there are plenty of regulations in certain setting that require us to disallow client applications from auto-filling form fields. We have to battle with the Web Platform authors to fill this niche and work around everything they put in our way to stop us from doing our job. Awesome. Personally I thought feature detection was a smell and was glad to see it going the way of the do-do in the early aughts. Not so glad to see it making a come back.
- izacus 9y ago> Regulatory compliance. I've worked on applications that had to go to great lengths to get the target browser platform to not do something like auto-complete authentication credentials. If I had a penny for every time I've heard this excuse for really terrible unsafe practices just to find out that the developer deliberately misinterprets it to make its job easier... it be rather rich now.
- TheCoelacanth 9y agoThose regulations are bad and user-hostile. If they are making it impossible to fulfill them, they are doing the right thing for their users.
- danaliv 9y ago> Regulatory compliance. > there are plenty of regulations in certain setting that require us to disallow client applications from auto-filling form fields. And which regulations would those be, specifically?
- agentultra 9y agoIf I recall in Part 11 compliance (which is how the FDA regulates software in the US) one is required to ensure that "Passwords are not remembered by [browsers] and applications." From an ISO/IEC/IEEE 29148 perspective the language might be "shall not remember passwords" which would imply a legally binding requirement for compliance purposes. This doesn't preclude applications from using autocomplete on form entry from password managers; just that the browser is not allowed to remember the entered password. However in practice I've seen most systems deploy their applications on a target platform that runs the browser in "kiosk" mode, which if I recall from the time, was an IE-only thing. In more modern times we're starting to see consumer-level tablets and devices enter the mix and I'm not even sure if those can be locked down into a multi-user/kiosk type mode. Regardless... the web is a difficult platform for this kind of stuff.
- explodingcamera 9y agoThere's a lot of confusion about autofill. Specifically for these user management interfaces etc. autocomplete="new-password" was introduced and as far as I know is supported in widely used browsers.
- lerpa 9y agoThis is like Internet Explorer way of doing things all over again. Instead of following the standard, just try to guess what people wanted to do, so you create a new standard.