Tutorials/Tips

Why you should disable autofill on your browsers

Completing an online order? Filling out another registration form? These are just some of the online tasks we’re happy to have autofill complete the information for us. Recently however, web developer Viljami Kuosmanen discovered a vulnerability that can expose your stored data to a malicious person via phishing.

In this attack, a phishing email would be sent asking the target to complete a form on a web page. Once the target fills out one of the (visible) fields, the browser then auto populates multiple invisible fields on the page (drawing from the stored autofill data).

Related Post:  How to install and configure Git on your favorite Linux distribution

Prevention against the attack

One of the most reliable is turning autofill off on your browser. It is easy to do, and if you’re using Chrome you can just follow these steps: Those steps for disabling auto-complete on Chrome are available here.

However, if you’re using Firefox, here are the steps you need to take to perform the same operation:

  • From the menu, select Edit > Preferences or click on the settings icon and select Preferences
  • Click on the Privacy panel, then from the drop-down menu next to Firefox will:, select Use custom settings for history
    Firefox search form history
    Figure 1: Disable saving search and form history on Firefox
  • Uncheck, or disable Remember search and form history
  • Close the settings tab
Related Post:  Running Node.js on Linux with systemd

Another feature that I highly recommend that you disable is saving login information. To disable it, take the following steps:

  • From the menu, select Edit > Preferences or click on the settings icon and select Preferences
  • Click on the Security panel, then under Logins, disable Remember logins for sites.
    disable auto-complete on Firefox
    Figure 2: How to disable auto-complete on Firefox

If you find saving login information an indispensable feature, at the very least use a master password to protect saved information.

LinuxBSDos needs your donation to continue!

I hope this article has saved you valuable time and effort to fix a problem that would have taken more time than is necessary. That makes me happy, and why I love doing this. But because more people than ever are reading articles like this with an adblocker, ad revenues have fallen to a level that's not enough to cover my operating costs. That's why I want to ask you a favor: To make a one-time or recurring donation to support this site and keep it going. It's a small favor, but every one counts. And you can make your donation using Patreon or directly via Paypal. Thank you for whatever donation you're able to make.

Donate via Patreon. Donate via Paypal.

Aside from donation, you may also signup to receive an email once I publish new content. Your email will not be shared or traded to anyone. And you can unsubscribe at any time.

Please share:

We Recommend These Vendors and Free Offers

Launch an SSD VPS in Europe, USA, Asia & Australia on Vultr's KVM-based Cloud platform starting at $5:00/month (15 GB SSD, 768 MB of RAM).

Deploy an SSD Cloud server in 55 seconds on DigitalOcean. Built for developers and starting at $5:00/month (20 GB SSD, 512 MB of RAM).

Want to become an expert ethical hacker and penetration tester? Request your free video training course of Online Penetration Testing and Ethical Hacking

Whether you're new to Linux or are a Linux guru, you can learn a lot more about the Linux kernel by requesting your free ebook of Linux Kernel In A Nutshell.


Leave a Comment

Your email address will not be published. Required fields are marked *

*