10

When there is no touch id on a device with touch id (when using an external display in clamshell mode), it doesn't prompt for the user password. https://cln.sh/pyKGOU

    3 months later

    Steps to reproduce:

    1. Close laptop and plug into external monitor. Touch ID should not be available since the lid is closed.
    2. Go to a website that you typically autofill passwords on. You'll be able to click on the autofill password without any need for authentication. Safari will ask for your device password in the same situation.

    Expected behavior:
    Asks for device password, or some other sort of authentication (could be an Orion PIN, whatever)

    Orion, OS version; hardware type:
    Orion Version 0.99.113.2-beta (WebKit 613.1.12)
    Bypass Paywalls Plugin, issue occurs even without plugin
    7-core M1 MacBook Air
    MacOS 12.3.1

      3 months later
      Merged 2 posts from Passwords don't require any authentication when Touch ID unavailable.
        4 months later

        Still an issue, this is a BIG security flaw!!!

        MacBook Pro (macOS Ventura 13.0 build 22A380)
        Version 0.99.122-beta (WebKit 615.1.11.7)

        • eirk replied to this.

          Npgiano this is not a security flaw really
          tmk, chrome didnt have this until very recently (not 100% sure) but it hasnt had this feature for a looong time

            eirk
            Doesn't matter what other browsers do, It's about expectations. If you expect a browser to be securely storing your passwords -- behind touch ID or authentication, then it should be secured throughout. If I logged into my banking app on my browser and it needed a username and password, only to log in on my phone and get in with just a username, that's a flaw! Orion secures your passwords behind Touch ID, but only with the lid open, then doesn't do anything to secure them when you close the lid!

            a year later

            When my macbook is in clamshell mode, it does not require input of a passcode or touchid in order input saved passwords.

            I expected to have to type in my password or something similar, not just have the password immediately input.

            Version 0.99.126.4.1.4-rc (WebKit 619.1.1)

            Sonoma (14)

              Merged 2 posts from Orion does not require password or touchid when in clamshell mode.
                2 months later
                23 days later

                @Vlad This is an issue (again/still). I just logged into some websites without any input but a click.

                • Vlad replied to this.

                  When I am in clamshell mode using an external monitor, the password filler does not require touchID to fill passwords

                    3 months later
                    No one is typing