Caută ajutor

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Acest fir de discuție a fost arhivat. Adresează o întrebare nouă dacă ai nevoie de ajutor.

What can I do to mitigate autofill attacks?

more options

Is password autofill for Firefox safe against the attacks outlined in

  https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/

Is there a way to make it safer?

Is password autofill for Firefox safe against the attacks outlined in https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/ Is there a way to make it safer?

Soluție aleasă

I don't know how widely this could be used, but one thing is for sure: if you set Firefox NOT to autofill logins, then an attack using an invisible form can't work. With that setting change, instead of having the username and password already in the boxes, you need to click the username box and select the username from a drop-down, and then Firefox fills the boxes. That tested out safe on that article's demo page.

Here's how to change the setting:

(1) In a new tab, type or paste about:config in the address bar and press Enter/Return. Click the button promising to be careful or accepting the risk.

(2) In the search box above the list, type or paste signon and pause while the list is filtered

(3) Double-click the signon.autofillForms preference to switch the value from true to false

Demo page: https://senglehardt.com/demo/no_boundaries/loginmanager/

Citește acest răspuns în context 👍 2

Toate răspunsurile (2)

more options
more options

Soluție aleasă

I don't know how widely this could be used, but one thing is for sure: if you set Firefox NOT to autofill logins, then an attack using an invisible form can't work. With that setting change, instead of having the username and password already in the boxes, you need to click the username box and select the username from a drop-down, and then Firefox fills the boxes. That tested out safe on that article's demo page.

Here's how to change the setting:

(1) In a new tab, type or paste about:config in the address bar and press Enter/Return. Click the button promising to be careful or accepting the risk.

(2) In the search box above the list, type or paste signon and pause while the list is filtered

(3) Double-click the signon.autofillForms preference to switch the value from true to false

Demo page: https://senglehardt.com/demo/no_boundaries/loginmanager/