Hacker News new | past | comments | ask | show | jobs | submit login

URLs should not contain PII data. That is a very bad design.

[Edit] I've got the wrong end of the stick it seems.




Where did I say URL? I'm talking a POST based form.

Put a value into it a text field and Chrome will helpfully save it for future auto-completion. Then it'll upload it to your account on their cloud if you're logged into an account. How do you think it's able to fill out your name, address, etc. on all those web forms?


I'm sorry. I'm out of date it seems. I thought autocomplete="false" worked for non authentication/non common fields. I'll have to check this out in the office later.


It looks as though Google have gradually eliminated support for this because "reasons" https://stackoverflow.com/questions/30053167/autocomplete-of...




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: