Autofill changes the phishing surface
Saved passwords that fill themselves in are genuinely useful, and they change what an attacker has to achieve.
The helpful version of this is worth knowing: a password manager fills a saved password only on the address it was saved for. Shown a convincing fake, it stays empty, which is a quiet and reliable signal that something is wrong. The unhelpful version is a browser that fills forms you did not notice were there, or offers details on a page that has no business asking for them. Noticing when autofill does not fire is a useful habit.
More on Browser security
- Same-origin policy limits which pages can read each otherSame room, different desks
- CORS relaxes browser reading rules, not authenticationA propped hatch, not a checkpoint
- SameSite cookies reduce some cross-site request risksSome journeys, not every journey
- Browser extensions inherit powerful visibilityEverything passes under it
- Local storage is convenient, not a secure vaultOpen shelves by the door
- Content Security Policy constrains script sourcesOnly from the addresses you wrote down
