10

Steps to reproduce:

  1. Close laptop and plug into external monitor. Touch ID should not be available since the lid is closed.
  2. Go to a website that you typically autofill passwords on. You'll be able to click on the autofill password without any need for authentication. Safari will ask for your device password in the same situation.

Expected behavior:
Asks for device password, or some other sort of authentication (could be an Orion PIN, whatever)

Orion, OS version; hardware type:
Orion Version 0.99.113.2-beta (WebKit 613.1.12)
Bypass Paywalls Plugin, issue occurs even without plugin
7-core M1 MacBook Air
MacOS 12.3.1

    3 months later
    Merged 2 posts from Passwords don't require any authentication when Touch ID unavailable.
      4 months later

      Still an issue, this is a BIG security flaw!!!

      MacBook Pro (macOS Ventura 13.0 build 22A380)
      Version 0.99.122-beta (WebKit 615.1.11.7)

      • eirk replied to this.

        Npgiano this is not a security flaw really
        tmk, chrome didnt have this until very recently (not 100% sure) but it hasnt had this feature for a looong time

          eirk
          Doesn't matter what other browsers do, It's about expectations. If you expect a browser to be securely storing your passwords -- behind touch ID or authentication, then it should be secured throughout. If I logged into my banking app on my browser and it needed a username and password, only to log in on my phone and get in with just a username, that's a flaw! Orion secures your passwords behind Touch ID, but only with the lid open, then doesn't do anything to secure them when you close the lid!

          a year later

          When my macbook is in clamshell mode, it does not require input of a passcode or touchid in order input saved passwords.

          I expected to have to type in my password or something similar, not just have the password immediately input.

          Version 0.99.126.4.1.4-rc (WebKit 619.1.1)

          Sonoma (14)

            Merged 2 posts from Orion does not require password or touchid when in clamshell mode.
              2 months later
              23 days later

              @Vlad This is an issue (again/still). I just logged into some websites without any input but a click.

              • Vlad replied to this.

                When I am in clamshell mode using an external monitor, the password filler does not require touchID to fill passwords

                  3 months later
                  No one is typing