Disable AutoComplete for JIRA login fields doesn't work

Walid Djama November 19, 2017

Hello,

i tried to disable autocomplete in login form of jira core 7.1.10 by following this link : 

https://confluence.atlassian.com/jirakb/how-to-disable-autocomplete-for-jira-login-fields-765399841.html 

Unfortunately it didn't work.

Any help please ? 

Best regards.

 

2 answers

0 votes
Walid Djama November 21, 2017

Hello, 

i communicated this information to the security team.

Thank you.

Best regards.

0 votes
Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
November 19, 2017

The doc works for one of our clients who wants to reduce their security this one, so the question is what you are doing differently to the doc?

And yes, I did say "reduce security".  Disabling autocomplete is a bad security pattern.  It encourages people to write down and reuse passwords and to use the most simple one they can.  Please, help them to be more secure by allowing them to use password safe software.

Rahul Krishna August 5, 2020

@Nic Brough -Adaptavist- I am sorry, i know this is almost 2 years old, but my security team did a penetration test and told me to disable AutoComplete for Jira login page. Is there anyway to do it?

Nic Brough -Adaptavist-
Community Leader
Community Leader
Community Leaders are connectors, ambassadors, and mentors. On the online community, they serve as thought leaders, product experts, and moderators.
August 6, 2020

Yes, but you absolutely should not do it.  Doing this will:

  • Render your Jira unsupported by Atlassian, which is a security issue as well as possibly a compliance one in many areas of business
  • Reduce the security of your system by getting users to write down passwords in plain text, use simple ones and reuse passwords they have for other systems

I cannot recommend doing it.  Please take those two points back to your security team and maybe question why they want you to be insecure.

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events