# UPS got into my browser's collection of email addresses

**URL:** https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475
**Category:** Factual Questions
**Created:** [August 24, 2012, 9:47am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475 "2012-08-24T09:47:10Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)
#### Post date: [August 24, 2012, 5:13pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/21 "2012-08-24T17:13:34Z")

</div>

There are people that have written things to steal the auto-complete list but they require you to interact with the browser to step through each entry. Basically they create a little game and every mouseclick in the game captures the next entry and because they setup the auto-complete field to be hidden from your view you don’t see what is happening.

---

<div class="post-metadata">

### Author: ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)
#### Post date: [August 24, 2012, 5:54pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/22 "2012-08-24T17:54:12Z")

</div>

> [@RaftPeople](#):
>
> There are people that have written things to steal the auto-complete list but they require you to interact with the browser to step through each entry. Basically they create a little game and every mouseclick in the game captures the next entry and because they setup the auto-complete field to be hidden from your view you don’t see what is happening.

Interesting. I really did not realize that the pcs are that secure that they can’t do this without the victim participating somehow. I’m grateful, but surprised. Are the warnings about malware overblown?

---

<div class="post-metadata">

### Author: ![Fubaya](https://avatars.discourse-cdn.com/v4/letter/f/c2a13f/32.png) [@Fubaya](https://boards.straightdope.com/u/Fubaya)
#### Post date: [August 24, 2012, 10:38pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/23 "2012-08-24T22:38:39Z")

</div>

Actually, all the autocomplete stuff is stored in a database file named formhistory.sqlite somewhere in your firefox directory. It contains one table “moz\_formhistory” and can be read with a single sqlite3 command “select \* from moz\_formhistory” (on linux anyway, I don’t know windows). If you get malware, it could easily read that file. While the data is readable, it doesn’t seem to be very interesting. The only things I see in mine are my name, address and phone number, google search terms and a LOT of crap. Malware could probably get more juicy info from reading your email or browser history than trying to sort through the garbage in the autocomplete file.

---

<div class="post-metadata">

### Author: ![RaftPeople](https://avatars.discourse-cdn.com/v4/letter/r/6f9a4e/32.png) [@RaftPeople](https://boards.straightdope.com/u/RaftPeople)
#### Post date: [August 24, 2012, 10:45pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/24 "2012-08-24T22:45:52Z")

</div>

> [@Keeve](#):
>
> Interesting. I really did not realize that the pcs are that secure that they can’t do this without the victim participating somehow. I’m grateful, but surprised. Are the warnings about malware overblown?

I never said pc’s are that secure. Of course warnings about malware are not overblown.

Are you being serious? (I really can’t tell)  
My post was merely related to the ability for a web page to get at the list - if you have an arbitrary program running on your system then yes, of course it can read that data.

---

<div class="post-metadata">

### Author: ![mhendo](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mhendo/32/3159_2.png) [@mhendo](https://boards.straightdope.com/u/mhendo)
#### Post date: [August 24, 2012, 11:18pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/25 "2012-08-24T23:18:01Z")

</div>

I had to check the thread date. I was sure that this must be a zombie from 1999 or something.

---

<div class="post-metadata">

### Author: ![smoke](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@smoke](https://boards.straightdope.com/u/smoke)
#### Post date: [August 25, 2012, 4:08pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/26 "2012-08-25T16:08:33Z")

</div>

This thread is awesome. **Keeve** , may I ask what your actual former programming experience is? I’m not gonna lie to you, I’m laughing a little at your understanding of auto-complete functionality. But I promise you I’m doing it in the most good-natured and non-dickish way possible. 🙂

---

<div class="post-metadata">

### Author: ![jtur88](https://avatars.discourse-cdn.com/v4/letter/j/e9c0ed/32.png) [@jtur88](https://boards.straightdope.com/u/jtur88)
#### Post date: [August 25, 2012, 6:26pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/27 "2012-08-25T18:26:16Z")

</div>

What UPS doesnt tell you while they are sucking you into filling all the forms, is that you will then have to pay $40 a year if you want any of the following services:

```
Manage and track all your home deliveries with a convenient, online calendar
Designate where you would like our driver to leave your package (e.g. back porch)
Get a confirmed two-hour window for home delivery
Reschedule the delivery of a package while you're on vacation
```

---

<div class="post-metadata">

### Author: ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)
#### Post date: [August 25, 2012, 7:14pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/28 "2012-08-25T19:14:22Z")

</div>

Even if you don’t submit the form, if you fill out a text field (or accidentally click one of the auto-complete entries), isn’t it possible that some rogue javascript would capture what’s in that text field and send it off? (But even that’d still just be one email address at a time, not the entire cached list.)

---

<div class="post-metadata">

### Author: ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)
#### Post date: [August 25, 2012, 8:40pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/29 "2012-08-25T20:40:27Z")

</div>

If someone could write a virus that can steal everything in your autocompletes, why couldn’t that same malicious programmer also just write a virus that steals _all_ the information that is stored on or passes through your computer? I mean, you use your computer for information that’s a lot more valuable than e-mail addresses. Like, for instance, the credit card number that you used to place that order on Amazon. If you’re so paranoid about this, why were you willing to type _that_ into your browser?

---

<div class="post-metadata">

### Author: ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)
#### Post date: [August 26, 2012, 3:47am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/30 "2012-08-26T03:47:01Z")

</div>

> [@smoke](#):
>
> This thread is awesome. **Keeve** , may I ask what your actual former programming experience is? I’m not gonna lie to you, I’m laughing a little at your understanding of auto-complete functionality. But I promise you I’m doing it in the most good-natured and non-dickish way possible. 🙂

Thanks, I appreciate it. From the early 80s to early 2000s I worked for several software houses on business applications - order entry, invoices, inventory, A/R and A/P. It was all in various versions of Basic, up to and including VB6. I wasn’t great at keeping my skills up to the market, and the switch to [VB.NET](http://VB.NET) knocked me out. All my experience involves one person entering/retrieving data from the system; nothing regarding interactions with other users, certainly not peering into other computers.

So, although I admit to being clueless about the abilities of 21st century viruses, I was fairly average for the late 20th century. (I still have a printout of a memo I wrote to my boss in 1985, about what would later be known as the Y2K problem.)

---

<div class="post-metadata">

### Author: ![Keeve](https://avatars.discourse-cdn.com/v4/letter/k/f07891/32.png) [@Keeve](https://boards.straightdope.com/u/Keeve)
#### Post date: [August 26, 2012, 3:53am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/31 "2012-08-26T03:53:28Z")

</div>

> [@Chronos](#):
>
> If you’re so paranoid about this, why were you willing to type _that_ into your browser?

You are totally correct, and I explicitly addressed this point in my last paragraph in post #20 above. Basically, it is my _hope_ that the credit-card number is in a very-temporary file, and gets deleted shortly after the transaction is complete. That doesn’t bother me as much as a list of information permanently stored in an easy-to-find place in my computer.

---

<div class="post-metadata">

### Author: ![spinky](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@spinky](https://boards.straightdope.com/u/spinky)
#### Post date: [August 26, 2012, 7:42am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/32 "2012-08-26T07:42:53Z")

</div>

> [@Reply](#):
>
> Even if you don’t submit the form, if you fill out a text field (or accidentally click one of the auto-complete entries), isn’t it possible that some rogue javascript would capture what’s in that text field and send it off? (But even that’d still just be one email address at a time, not the entire cached list.)

Yes, it’s untrue that you must submit the form in order for a site to read what you’ve typed into it (or what you’ve selected from the autocomplete menu) if you have javascript enabled. It can’t automatically pull stuff out of the autocomplete menu; the act of choosing it from the menu puts it into the field just as if you had typed it, and then the javascript on the page could see it and transmit it to the server without you submitting the form.

---

<div class="post-metadata">

### Author: ![ZenBeam](https://avatars.discourse-cdn.com/v4/letter/z/3ab097/32.png) [@ZenBeam](https://boards.straightdope.com/u/ZenBeam)
#### Post date: [August 26, 2012, 3:16pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/33 "2012-08-26T15:16:14Z")

</div>

> [@Keeve](#):
>
> You are totally correct, and I explicitly addressed this point in my last paragraph in post #20 above. Basically, it is my _hope_ that the credit-card number is in a very-temporary file, and gets deleted shortly after the transaction is complete.

I do wonder about this. I don’t recall seeing my credit card number in an auto-complete box. I’ve seen email address, my username and password, my real name, my city, my zip code, but I don’t think I’ve seen my CC number.

---

<div class="post-metadata">

### Author: ![Telemark](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/telemark/32/372_2.png) [@Telemark](https://boards.straightdope.com/u/Telemark)
#### Post date: [August 26, 2012, 4:02pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/34 "2012-08-26T16:02:54Z")

</div>

> [@ZenBeam](#):
>
> I do wonder about this. I don’t recall seeing my credit card number in an auto-complete box. I’ve seen email address, my username and password, my real name, my city, my zip code, but I don’t think I’ve seen my CC number.

I have, and it’s poor coding on someone’s part.

---

<div class="post-metadata">

### Author: ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)
#### Post date: [August 26, 2012, 6:32pm UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/35 "2012-08-26T18:32:34Z")

</div>

> [@ZenBeam](#):
>
> I do wonder about this. I don’t recall seeing my credit card number in an auto-complete box. I’ve seen email address, my username and password, my real name, my city, my zip code, but I don’t think I’ve seen my CC number.

Most website creators are smart enough to disable autocomplete for CC fields (it’s a “autocomplete=off” setting they have to remember to use). Otherwise you get what Telemark experienced.

---

<div class="post-metadata">

### Author: ![AaronX](https://avatars.discourse-cdn.com/v4/letter/a/7bcc69/32.png) [@AaronX](https://boards.straightdope.com/u/AaronX)
#### Post date: [August 27, 2012, 4:21am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/36 "2012-08-27T04:21:38Z")

</div>

> [@Keeve](#):
>
> For the same reason I rarely allow my browser to remember my password. It’s a pain having to type it, but relatively safer.

I’m not sure this is true. What if you get a keylogger program? After the infection, it gets whatever passwords you type. But if you use your browser to store passwords, all you’re typing is your browser password, which is useless to anyone without your computer.

---

<div class="post-metadata">

### Author: ![JpnDude](https://avatars.discourse-cdn.com/v4/letter/j/838e76/32.png) [@JpnDude](https://boards.straightdope.com/u/JpnDude)
#### Post date: [August 27, 2012, 5:36am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/37 "2012-08-27T05:36:53Z")

</div>

In Japan, for a small extra fee, Amazon.co.jp is able to deliver certain products to local convenience stores for collection. 🙂

---

<div class="post-metadata">

### Author: ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)
#### Post date: [August 27, 2012, 5:57am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/38 "2012-08-27T05:57:34Z")

</div>

> [@AaronX](#):
>
> I’m not sure this is true. What if you get a keylogger program? After the infection, it gets whatever passwords you type. But if you use your browser to store passwords, all you’re typing is your browser password, which is useless to anyone without your computer.

Well, you’re trading one risk for another. If your computer is infected, the malware could just as easily steal your entire saved password file as it could log your future keystrokes. Or both.

---

<div class="post-metadata">

### Author: ![Jragon](https://avatars.discourse-cdn.com/v4/letter/j/e19b73/32.png) [@Jragon](https://boards.straightdope.com/u/Jragon)
#### Post date: [August 27, 2012, 8:05am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/39 "2012-08-27T08:05:21Z")

</div>

> [@AaronX](#):
>
> I’m not sure this is true. What if you get a keylogger program? After the infection, it gets whatever passwords you type. But if you use your browser to store passwords, all you’re typing is your browser password, which is useless to anyone without your computer.

Doesn’t autocomplete in general actually make you safer from a keylogger?

Let’s say my email address is [noparse]abc@gmail.com[/noparse], sure, if I type that whole thing in then they’ll see my email. But if I’ve been using autocomplete the keylogger will just see

ab\<DOWN ARROW\>\<ENTER\>

Hell, storing all your passwords in plaintext on your computer makes a keylogger almost useless, all they’ll ever see you enter is Ctrl+C, Ctrl+V.

Unless I’m taking “keylogger” too literally and modern keyloggers do more than their names imply.

---

<div class="post-metadata">

### Author: ![grude](https://avatars.discourse-cdn.com/v4/letter/g/e47774/32.png) [@grude](https://boards.straightdope.com/u/grude)
#### Post date: [August 27, 2012, 8:25am UTC](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475/40 "2012-08-27T08:25:27Z")

</div>

I use the same yahoo webmail email address with facebook, and anyone I send an email to or receive one from shows up as a potential friend in facebook!

This really creeped me out the first time I said where did all these people come from?

[Previous page](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475.md?page=1)

[Next page](https://boards.straightdope.com/t/ups-got-into-my-browsers-collection-of-email-addresses/632475.md?page=3)
