3 ms·
I don't see how this is a security hole, unless the website gets hacked in another way. Every time you sign up for an account the website could save your passwo
by 12345j 14y ago
I don't see how this is a security hole, unless the website gets hacked in another way. Every time you sign up for an account the website could save your password in plaintext which they could view later. Same thing for signing in, a website could just save the submitted password.
If for some reason my logic is flawed, then a lot of information would have to be denied, essentially and operation on a password input. You'd have to disable and .type, .val, and probably a couple of others on password fields.
- herge 14y agoMaybe it's proof that you should host your own version of jQuery instead of trusting, say, the google cdn.
- homakov 14y agoyou didn't get it. i want to deny access to PREFILLED stuff. no user interaction at all
- 12345j 14y agoIf a script wants to gain access to the prefilled stuff it has to come from the website creator unless the website is hacked with sql injection or something like that, which still has the same problem- if they really want your password, on signin the website can just get the password value of the form and save it somewhere,.
- Tichy 14y agoMost websites include a host of javascript from other sites, like Google Analytics, Like-Buttons, Ads, and so on. If they all can get to the password it seems like an issue to me. Personally I am surprised by this. Afaik you can not copy+paste the password from a password form field, so I just somehow assumed you couldn't get to it via JavaScript, either.
- homakov 14y agogood analogy with copy paste