I don’t know whether or not Firefox even allows JavaScript access to the passwords automatically filled out when you visit a page, but I sure am not going to wait until some cracker finds a hole in whatever security Firefox provides and gets at my automatically-entered password.
So, this time around I’ve decided to require Firefox to wait until I’ve entered the username before the password is filled out. If I forget the username, I simply hit the down arrow in the username box and it gives me a selection.
The setting is located at about:config (for those who don’t know: type that into the address bar) and is called “signon.autofillForms”. I set it to false. Long may security prosper!