[imp] Windows XP caches login credentials.

Eric Rostetter eric.rostetter@physics.utexas.edu
Thu, 18 Jul 2002 09:40:56 -0500


Quoting Andreas Dahlén <andreas@dahlen.ws>:

> Citerar Michael M Slusarz <slusarz@bigworm.colorado.edu>:
> 
> > Are you going to do this via a $browser->quirk() call? (Can we grab
> > OS information from IE browser headers?)
> > 
> 
> Setting autocomplete="off" is also valid for Mozilla and Netscape 6.x.
> For a form with autocomplete="off" there is no question if you wants
> to save the contens of the fields.  I think that it should be set for
> all browsers.
> 
> /Andreas

I think we should consider security above user choice here.  So in general
I support adding the tag to login forms.  My only objection is, as someone
noted, that it is not xhtml complaint.  But it certainly would help the
security rating of Horde/IMP (for those using it in public places, shared
web browsers, etc).

-- 
Eric Rostetter
The Department of Physics
The University of Texas at Austin

"TAD (Technology Attachment Disorder) is an unshakable, impractical devotion
to a brand, platform, product line, or programming language. It's relatively
harmless among the rank and file, but when management is afflicted the damage
can be measured in dollars. It's also contagious -- someone with sufficient
political clout can infect an entire organization."

--"Enterprise Strategies" columnist Tom Yager.