camillelamy / explainers

11 stars 5 forks source link

Anonymous iframes: autocomplete #17

Open annevk opened 3 years ago

annevk commented 3 years ago

It seems somewhat "reasonable" for a user to expect they are not being phished if autocomplete works for the login in the third party context. So that might have to be explicitly disabled along with warnings.

camillelamy commented 3 years ago

Thanks! I have updated the explainer to reflect that we will want to disable autofill/password manager functionalities for these frames.