Open annevk opened 3 years ago
It seems somewhat "reasonable" for a user to expect they are not being phished if autocomplete works for the login in the third party context. So that might have to be explicitly disabled along with warnings.
Thanks! I have updated the explainer to reflect that we will want to disable autofill/password manager functionalities for these frames.
It seems somewhat "reasonable" for a user to expect they are not being phished if autocomplete works for the login in the third party context. So that might have to be explicitly disabled along with warnings.