10.13.4: restore old Autofill behavior for usernames and passwords

Discussion in 'macOS High Sierra (10.13)' started by exi, Mar 30, 2018.

  1. exi macrumors 6502

    Joined:
    Oct 16, 2012
    #1
    With this latest round of updates, I've noticed that 10.13.4 makes it such that specifying to autofill my password on saved sites is necessary when the page loads. Same on iOS 11.3.

    Prior to 10.13.4 / iOS 11.3, usernames AND passwords would automatically populate on page load if saved and Safari was configured to do so, essentially saving a click or two.

    Is there a way to restore that behavior (in either macOS or iOS)?

    I've read that it is possible for malicious sites to obtain login credentials if they are in those fields even if the user doesn't click "submit" / "login" / etc, although I'm unfamiliar with how that might work and am not sure if it would be a significant risk with my use case. Have looked but haven't seen how/if possible.

    Thanks in advance.
     
  2. CaTOAGU, Mar 30, 2018
    Last edited: Mar 31, 2018

    CaTOAGU macrumors 6502a

    Joined:
    Jul 15, 2008
    Location:
    Manchester, UK
    #2
    The risk is simply from using auto fill to fill out passwords, the attack can reveal passwords for any site for which credentials are stored, not just the one you’re currently visiting. Anyone who uses Safari in this way is affected and at risk, I wouldn’t change it back, even if you found a way.
     
  3. exi thread starter macrumors 6502

    Joined:
    Oct 16, 2012
    #3
    Interesting. I'm usually pretty good on keeping up with such things, but that's something in terms of the breadth of vulnerability -- have a link you could share on how this works technically? News to me.
     

Share This Page