22 July 2010 17:45 GMT / By Paul Lamkin
Safari users - turn off your AutoFill option at once. It's probably on as this is the default setting.
9 to 5 Mac is reporting that by leaving the feature on, you are opening yourself up to a world of cyber nasties, just waiting to steal all of your details.
Jeremiah Grossman details how the security glitch happens:
"These fields are AutoFill'ed using data from the users personal record in the local operating system address book. Again it is important to emphasize this feature works even though a user never entered this data on any website.
"Also this behaviour should not be confused with normal auto-complete data a Web browser may remember after its typed into a form. All a malicious website would have to do to surreptitiously extract Address Book card data from Safari is dynamically create form text fields with the aforementioned names, probably invisibly, and then simulate A-Z keystroke events using JavaScript.
"When data is populated, that is AutoFill’ed, it can be accessed and sent to the attacker. The entire process takes mere seconds and represents a major breach in online privacy. This attack could be further leveraged in multi-stage attacks including email spam, (spear) phishing, stalking, and even blackmail if a user is de-anonymized while visiting objectionable online material".
The security flaw has been known about for a year now although it isn't yet clear why it has taken so long for knowledge to reach the public domain.
But you know now, so get it turned off.
Via: 9to5mac.com
Software, Browsers, Safari, Macs



APP OF THE DAY: Tom Daley Dive 2012 review (iPad / iPhone / iPod touch) Splooosh!
Sony Vaio E Series pictures and hands-on Everyday laptops
Motorola RAZR MAXX pictures and hands-on "Longest talktime of any smartphone"
Canon EOS 650D coming in June - specs leaked About time and all
Lego creates exclusive Team GB Olympic minifigs Going for gold
Diablo III collector's edition pictures and hands-on
Sony Vaio T13 Ultrabook pictures and hands-on Sony's first Ultra
Sony Vaio S Series pictures and hands-on 13-incher fondled
Want to transfer Android apps to a Windows Phone? Microsoft would like to help Showing App-titude
Samsung Galaxy S III receives 9 million pre-orders Are you one of the crowd?
ICANN and the dot anything: do we care about domain names? The web is changing
Sony: The 4K video revolution is at tipping point EXCLUSIVE: Content will follow home tech
Olympic diving hope Tom Daley gets own iOS game Tom Daley Dive 2012
HTC Evo 4G LTE Pro Evo?
Cisco Linksys X3000 One for basic users
Olympus OM-D E-M5 review
The compact system camera to beat all others?
Nokia Lumia 900 review
Is big beautiful?
HTC One V review
V for victory?
Huawei Ascend G300 review
Big bang for your hundred quid
FIFA 12: UEFA Euro 2012 review
Lacks polish, if not the Polish
Asus Transformer Pad TF300T review
Transforms your money in to a great tablet
BlackBerry Mini Keyboard for PlayBook review
Will this make working on the go easier?
Fujifilm X-Pro1 review
Like a Leica
Nikon Coolpix P510 review
Does the P510 zoom beyond expectations?
Volkswagen Beetle Design 1.2TSi DSG review
The bug is back. Again.
The Walking Dead: The Game review
Fleshed out zombie bonanza
HP Envy 14 Spectre review
The Ultrabook that isn't an Ultrabook
Nikon Coolpix S6300 review
Point, shoot and scoot
Fujifilm FinePix HS30EXR review
Can Fujifilm’s latest put the ‘super’ in superzoom?