Do Not Use Password Managers’ Automatic Autofill Feature

I keep seeing the following request among people using password managers: “I’m looking for a new password manager because [Bitwarden|LastPass|1Pass|etc.] doesn’t handle automatic autofill correctly on my computer/phone.”

Do not use automatic autofill. Ever.

If your password manager defaults to automatic autofill being on, or you turned it on manually, you need to disable that. Automatic autofill adds unacceptable security risks that aren’t worth it for the minimal time it saves.

The risk is that a third party script, such as from an ad, could surreptitiously collect the data from the automated autofill without the user ever being aware of the security compromise.

For example, there was a vulnerability in the Android applications for 1Password and LastPass that would have allowed malicious apps to use the automated autofill feature to exfiltrate a user’s login and password.

Leave a Reply