搜尋 Mozilla 技術支援網站

防止技術支援詐騙。我們絕對不會要求您撥打電話或發送簡訊,或是提供個人資訊。請用「回報濫用」功能回報可疑的行為。

Learn More

What can I do to mitigate autofill attacks?

more options

Is password autofill for Firefox safe against the attacks outlined in

  https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/

Is there a way to make it safer?

Is password autofill for Firefox safe against the attacks outlined in https://freedom-to-tinker.com/2017/12/27/no-boundaries-for-user-identities-web-trackers-exploit-browser-login-managers/ Is there a way to make it safer?

被選擇的解決方法

I don't know how widely this could be used, but one thing is for sure: if you set Firefox NOT to autofill logins, then an attack using an invisible form can't work. With that setting change, instead of having the username and password already in the boxes, you need to click the username box and select the username from a drop-down, and then Firefox fills the boxes. That tested out safe on that article's demo page.

Here's how to change the setting:

(1) In a new tab, type or paste about:config in the address bar and press Enter/Return. Click the button promising to be careful or accepting the risk.

(2) In the search box above the list, type or paste signon and pause while the list is filtered

(3) Double-click the signon.autofillForms preference to switch the value from true to false

Demo page: https://senglehardt.com/demo/no_boundaries/loginmanager/

從原來的回覆中察看解決方案 👍 2

所有回覆 (2)

more options
more options

選擇的解決方法

I don't know how widely this could be used, but one thing is for sure: if you set Firefox NOT to autofill logins, then an attack using an invisible form can't work. With that setting change, instead of having the username and password already in the boxes, you need to click the username box and select the username from a drop-down, and then Firefox fills the boxes. That tested out safe on that article's demo page.

Here's how to change the setting:

(1) In a new tab, type or paste about:config in the address bar and press Enter/Return. Click the button promising to be careful or accepting the risk.

(2) In the search box above the list, type or paste signon and pause while the list is filtered

(3) Double-click the signon.autofillForms preference to switch the value from true to false

Demo page: https://senglehardt.com/demo/no_boundaries/loginmanager/