DEV Community

Cover image for Researchers Found Your Password Leaking Before You Even Hit Submit
Short Lived
Short Lived

Posted on Originally published at shortlivedage.substack.com AI-assisted

Researchers Found Your Password Leaking Before You Even Hit Submit

What the research found

A 2022 study crawled the top 100,000 websites, filling in email and password fields on forms and then monitoring network traffic without ever clicking submit. On 1,844 sites tested from the EU and 2,950 from the US, the typed email address was sent to a tracking, marketing, or analytics domain before the form was submitted and without any consent given. The researchers also found 41 tracking domains doing this that weren’t listed on any of the popular ad-blocker filter lists people count on for protection. Rejecting a cookie consent banner made almost no difference to whether the leak happened.

The bigger finding involved passwords. On 52 websites, typed passwords were captured by third-party session replay scripts, tools built to record a visitor’s on-page behavior for customer-experience analysis. Most of these leaks traced back to a single vendor’s script that was supposed to filter password fields out of what it recorded, and didn’t. Seven of the affected sites ranked among the top 20,000 most visited websites in the world, including a major bank’s site.


Why closing the tab doesn’t undo it

Most people’s mental model of a web form is that nothing happens until you click submit, so backing out or closing the tab feels like a clean exit. Session replay and form-tracking scripts don’t work on that logic. They can read what’s typed into a field as it’s typed, apart from whether the form is ever completed. A password manager’s autofill, a half-finished signup you abandoned, a login you started and reconsidered: any of these can already be captured before you decide not to go through with it.


The practical takeaway

Treat information typed into a web form as visible the moment you type it, not only after you submit, on sites you don’t fully trust in particular. A password manager that fills fields for you rather than requiring you to type them by hand cuts down this specific exposure to some degree, since less of what’s captured is raw keystrokes. If you started filling out a form and decided against continuing, that decision doesn’t undo what you already typed, so hold off on entering real information into a field until you’re ready to submit it.

The vendor most responsible for the password-leak findings fixed the issue after the researchers reported it, and browser vendors and privacy tools have added detections for some of this behavior since the study was published. The specific sites named in this research may no longer be affected. The underlying technique, and the fact that consent banners don’t stop it in any reliable way, remains a current risk across the web.


Reference

Senol, A., Acar, G., Humbert, M., Zuiderveen Borgesius, F. “Leaky Forms: A Study of Email and Password Exfiltration Before Form Submission.” Proceedings of the 31st USENIX Security Symposium, 2022. https://www.usenix.org/system/files/sec22fall_senol.pdf

Support Me on Ko-fi

Top comments (0)