8 ms·
Unfortunately a few developers are morons who misuse features, and browser vendors try hard to work around them. Case in point, lots of websites used to put `au
by klmr 7y ago
Unfortunately a few developers are morons who misuse features, and browser vendors try hard to work around them. Case in point, lots of websites used to put `autocomplete="off"` on password boxes, which breaks some password managers. IIRC that’s why Chrome (and other browsers) decided to sometimes ignore the `autocomplete` attribute in the first place. Of course that doesn’t justify ignoring it completely (just for password fields) but maybe a similar reason is at play.
- onli 7y agoExactly. Autocomplete=off gets misused. For example, there was a browsergame I played where because of idiotic "security considerations" autocomplete=off got applied to the login screen. At that time for me that meant typing in the password manually, thus picking a bad password. So it's a good thing in that situation when the browser ignores the attribute.
- scient 7y agoVery egoistic and ignorant way of viewing things. Disabling autocomplete on login screens has its uses, especially on any app that has shared-terminal type of use, where you cannot trust the user to make the smart choice of not remembering their password - or evening exposing the previous users emails that were used. You picking a bad password has nothing to do with this feature.
- onli 7y agoNo, it does not have its uses in those scenarios. Every website with login could be used in such a scenario, in an internet cafe for example. It's not on the web developer to predict this, it's on the terminal to prevent that issue. It has its uses in some very limited scenarios, like a password field in a blog editor that when set locks the article for users not knowing the password. But that's not a login screen. Me picking a bad password was absolutely caused by this misuse of autocomplete=off, it had everything to do with it. How can you claim otherwise? I was there, you were not.
- TurningCanadian 7y agoThat was even mandated for all password fields by the PCI scans required for any sites accepting credit cards.
- erichurkman 7y agoNow they need to ban intercepting/blocking `onpaste` in form fields.
- antisemiotic 7y agoThis has the added benefit of disabling local password managers like PasswordSafe. Might as well throw in some stupid password policy (like maximum password length, or banning some special characters but not explaining which) to make sure stubborn users won't use a secure password even if they're willing to type it in every time.
- vorpalhex 7y agoAs an fyi, you can disable the onpaste event in the dev console. Obviously doesn't fix the actual problem but at least helps retyping your email...