When to disable the "save password" function in your login form?

I have a public website that is used to manage business infrastructure equipment for my clients. A security breach on this website can cause expensive problems for customers.

Several different websites - mainly banks, healthcare and government - disable the "save password" dialog from Firefox, IE, and other browsers, citing security concerns. I'm talking about the box / bar that appears after entering your login information, so the browser can automatically fill in the username and password fields the next time you visit this site.

My question is not how to disconnect, because the answer is Disable browser "Save password" .

What I want to know:

  • What are some cases where it is absolutely necessary to disable the "save password" functionality? Are there such cases?
  • Does this technique really provide added security? In other words, people will not find a way to leak their passwords, despite your efforts?
  • Do users complain about the removal of the "save password" functionality?
  • Any other thoughts on when to disable the "save password" functionality?
+3
source share
8 answers

;-) , - , .

, , , , , - , , - , , , - , , , , . - , . , - , . ( Firefox Javascript)

, , , erm, . (, , ) -, , .

+10

: ,

  • - , , - uhm, - .
  • /, - , (, Whateverbook),

, - . -, , , , . , .

" "?

, . , .

+5

1) " , " "? ?"

. , , . , - , - . , , .

2) " ? , , ?"

. . . , , , , -, . .

3) " "?

. , , . , , , . , - , , , .

4) , " "?

1). / .

+2

:

  • ?

- , , , , .

- , . , , , , .

  • ?

- , , . .

-, , , , , . , .

, :

  • Ebay
  • , , .
  • / , .
+2

. , . :

  • - .
  • ,
  • , , .

, 3, .

+1

( " " ), . ( A [ -], , B , . , A ).

, ( Windows ..), "" , - .

+1

. , - , , , , .

, , .

.

+1

, , . , .

0

Source: https://habr.com/ru/post/1704636/


All Articles