All the prompts for MFA codes store previous results, which is useless and gets in the way, since there is almost no chance that you will ever re-use the same code. Please disable this, so that the UI stops making suggesting and showing previous results.
In theory, it is also a security risk, although the likely hood of that actually being exploited are likely very low.
| Idea priority | Medium |
By clicking the "Post Comment" or "Submit Idea" button, you are agreeing to the IBM Ideas Portal Terms of Use.
Do not place IBM confidential, company confidential, or personal information into any field.
Obviously you can decide to never fix it, but this behavior can not be realistically switched off for a single form in the browser. Suggesting the fix for everyone is to broadly disable the functionality of their browser for the whole IBM site or all sites in general instead of labeling the field correctly in the HTML/javascript seems silly. In general this should be as easy as this:
And this basic use-case is undeniable the exact reason that the autocomplete option exists in forms.
Marking as will not implement. This can be switched off in the browser, and there is no real vulnerability here as far as codes being reused goes. No development resources are available to address this at present.
MFA for IBM cloud (cloud.ibm.com), Softlayer (control.softlayer.com) and likely Bluemix (control.bluemix.com). A picture has been attached showing the issue on the IBM Cloud login screen.
Is this in references to MFA for the platform or with the App ID service ?