« Belkin spam-routers | Main | Syncato TrackBack test »

Safari auto-fill considered harmful

The buggy form auto-fill feature in Safari has put me in trouble in the past as I reported already. But here is another nasty strike that just happened while I was adding a comment on this site:

safariautofill.gif

As you can see, had I not seen the pre-filled URL, I would have spammed my own weblog! It's a chance I caught it before submitting the form, as normally this information is pre-filled using a cookie. I guess that Safari decided that the URL field had to be filled with the information of the last comment-spam I had deleted before.

If you are using the auto-fill feature in Safari, you'd better double check what it decides to fill in itself!

Update: in the AutoFill Web Forms preferences, I unchecked Other Forms to prevent Safari from filling out anything but personal info and authentication forms. It didn't prevent Safari from continuing to autofill "other forms" as usual (like when I delete a comment spam on MT). I really don't like that.

TrackBack

TrackBack URL for this entry:
http://padawan.info/cgi-bin/mt/mt-trckbck.cgi/557

Comments (2)

Don:

Good catch!

My personal rule:

"Never use autofill, it is a security flaw in the various browsers".

Each time I help somebody to install or reinstall his computer and the dialog "Do you want autofill" shows up, I click "No" and I explain why.

About

This page contains a single entry from the blog posted on November 8, 2003 6:32 PM.

The previous post in this blog was Belkin spam-routers.

The next post in this blog is Syncato TrackBack test.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 4.01