QuickTold: Safari form autocomplete feature leaks personal information.
Tip by /g/ - United Tech Support Service, Anonymous | Added 2010-07-23, 11:30 PM | 18 Replies
Have news of Apple getting told? Found a Mac user making an arrogant comment on a forum somewhere? Send it in!
Status as of 04:20 PM: Apple TOLD | Microsoft TOLD | AT&T TOLD | Intel TOLD | AMD TOLD | Nvidia NOT TOLD
| > |
Anonymous 07/24/10(Sat)00:18 No.8531
ToldNet: No functions currently available.
>I know who your name |
| > |
Anonymous 07/24/10(Sat)00:27 No.8533
ToldNet: No functions currently available.
Hahaha. Oh wow. |
| > |
Chimecho 07/24/10(Sat)00:46 No.8534
ToldNet: No functions currently available.
And to think, Safari was always the first browser to be hacked at pwn2own too. |
| > |
Anonymous 07/24/10(Sat)00:46 No.8535
ToldNet: No functions currently available.
>>8533 |
| > |
Anonymous 07/24/10(Sat)07:19 No.8539
ToldNet: No functions currently available.
There's no security issue. Just don't surf that way. |
| > |
Anonymous 07/24/10(Sat)15:06 No.8542
ToldNet: No functions currently available.
Not surfing that way? It should be off by default and perhaps prompt users with an explanation of the feature and risks first opportunity it can be used. |
| > |
Anonymous 07/24/10(Sat)15:20 No.8544
ToldNet: No functions currently available.
So the leak is caused by auto-fill filling in fields? I don't understand the issue here. |
| > |
Anonymous 07/24/10(Sat)15:27 No.8546
ToldNet: No functions currently available.
>>8544 |
| > |
Anonymous 07/24/10(Sat)15:34 No.8547
ToldNet: No functions currently available.
>>8544 |
| > |
Anonymous 07/24/10(Sat)16:27 No.8548
ToldNet: No functions currently available.
>>8547 |
| > |
Anonymous 07/24/10(Sat)17:23 No.8549
ToldNet: No functions currently available.
It's like everything Apple makes is designed to tell everyone who you are now. Not surprising really. |
| > |
Anonymous 07/24/10(Sat)21:45 No.8553
ToldNet: No functions currently available.
>>8539 |
| > |
Anonymous 07/26/10(Mon)12:47 No.8555
ToldNet: No functions currently available.
This is a serious attack and the fact that sites can trigger autocomplete, then retrieve the form data without user submission is pretty glaring and appalling design practice. There's a lot of "TODO"s in the WebKit source though, so I'm not surprised. |
| > |
Anonymous 07/27/10(Tue)16:06 No.8556
ToldNet: No functions currently available.
>I know who your name |
| > |
Anonymous 07/27/10(Tue)22:34 No.8557
ToldNet: No functions currently available.
>>8555 |
| > |
Anonymous 07/27/10(Tue)22:42 No.8558
ToldNet: No functions currently available.
>>8557 |
| > |
Anonymous 07/27/10(Tue)23:52 No.8559
ToldNet: No functions currently available.
Daily Price Told: |
| > |
Anonymous 07/28/10(Wed)00:30 No.8560
ToldNet: No functions currently available.
And nothing of value was lost. |
