Safari users beware: Default settings are dangerous

Turn off your AutoFill

Safari users beware: Default settings are dangerous

22 July 2010 17:45 GMT / By Paul Lamkin

Safari users - turn off your AutoFill option at once. It's probably on as this is the default setting.

9 to 5 Mac is reporting that by leaving the feature on, you are opening yourself up to a world of cyber nasties, just waiting to steal all of your details.

Jeremiah Grossman details how the security glitch happens:

"These fields are AutoFill'ed using data from the users personal record in the local operating system address book. Again it is important to emphasize this feature works even though a user never entered this data on any website.

"Also this behaviour should not be confused with normal auto-complete data a Web browser may remember after its typed into a form. All a malicious website would have to do to surreptitiously extract Address Book card data from Safari is dynamically create form text fields with the aforementioned names, probably invisibly, and then simulate A-Z keystroke events using JavaScript.

"When data is populated, that is AutoFill’ed, it can be accessed and sent to the attacker. The entire process takes mere seconds and represents a major breach in online privacy. This attack could be further leveraged in multi-stage attacks including email spam, (spear) phishing, stalking, and even blackmail if a user is de-anonymized while visiting objectionable online material".

The security flaw has been known about for a year now although it isn't yet clear why it has taken so long for knowledge to reach the public domain.

But you know now, so get it turned off.

Via: 9to5mac.com

Full tags
Software, Browsers, Safari, Macs

share print story pdf email story

Recommended articles

Recommended articles from around the web

Loading

Best iPad 2 apps

We detail the best iPad 2 and iPad apps in the app store Which iPad app should you download?

Best new iPad apps

We detail the best iPad apps in the app store for your new Retina Display Which iPad app should you download?

Windows 8

First Look: Windows 8 Consumer Preview reviewed

The new iPad

The new iPad: Everything you need to know

Pocket-lint poll

Q. Does the Samsung Galaxy S III deliver what you hoped for?

Vote YES Vote NO

» LAST TIME
When asked Would you switch from iOS to Android? 54% said yes and 46% said no