4 ms·
I always assumed it was for the same reason sites make you enter your email address twice without pasting - to reduce the chance of mistyping. If you only have
by level3 10y ago
I always assumed it was for the same reason sites make you enter your email address twice without pasting - to reduce the chance of mistyping. If you only have to enter something once, then you could easily mistype it and then you end up with an account you can't log in to or even recover. But if you have to type it twice, then the chance is greatly reduced, since you'd have to make the exact same typo twice in a row.
Edit: This is regarding account creation/changes like the PayPal example. I have no idea why login forms would disallow pasting.
- morgante 10y agoThat's still not a very good reason. If you're security conscious, you shouldn't be typing passwords at all. You should generate them from a password manager and paste them into the field both times. It boils down to security theater making us all less secure.
- madeofpalk 10y agoNot concerned about security, but about the direct user experience. The user won't know that they've mistyped their password, won't potentially won't return when they can't log into their account.
- Retr0spectrum 10y agoWhy not just disallow copying from the first field? That way, password manager users can paste into both fields, but users who are hand-typing are forced to avoid mistakes.
- makomk 10y agoSites already do, but that doesn't stop users from copy-and-pasting from password generators or typing the password elsewhere and copy-and-pasting that twice.
- Retr0spectrum 10y agoEnabling the use of password managers is a good thing. A user typing the password elsewhere probably means they were able to see it while they type, and are therefore less likely to make a mistake.
- level3 10y agoAs someone running a user-facing site, you cannot control whether your users use password managers. So what's your solution? Just disregard the segment of your users who don't use password managers? That's a tradeoff that you might not want to make, depending on your business. Also, if you're someone who uses a password manager, does disabling pasting really make you less secure? I assume you're still generating passwords; you just have to retype them. So maybe less convenient, but less secure is kind of a stretch. (By the way, I personally use KeePass, and I generally use auto-type instead of pasting, so I'm not inconvenienced at all.)
- raldi 10y ago> So what's your solution? Allow pasted passwords if they meet a very high password-quality heuristic; deny them if they seem too guessable.
- level3 10y agoHow is that a solution to the problem of user error (i.e. mistyping)? Are you making an implicit assumption about password manager use and mistyping, that somehow your heuristic will be able to differentiate? That seems like a lot of work for something that may be prone to mistakes, while also delivering an inconsistent user experience, for the sake of some (unstated) assumptions about security that may not be founded.
- morgante 10y agoIt actually makes a lot of sense. People will almost never manually type out high security (>20 random characters) passwords themselves. So if someone enters a high entropy password, you can fairly confident that mistyping is not an issue.
- level3 10y agoI'm not quit convinced about that. 1) Aren't there people using generators like Diceware that don't do the password management part? 2) The industry's definition of "high security" is constantly changing. Password strength measurement makes assumptions about what is and isn't guessable, and a lot of that depends on what techniques the common brute-force crackers are employing. So finding the right heuristic is also problematic.
- ioquatix 10y agoIf you are security conscious at all, you'd be generating a public/private key pair for website authentication, only using HTTPS and potentially preferring TOR. I mean, a username+password field is SO FAR from good security practices, it's almost a joke.
- morgante 10y agoI assume you're being farcical, but I would love if more sites offered authentication schemes beyond usernames and passwords. These days, I will refuse to log in to any website which doesn't support https.
- XorNot 10y agoI'd like APIs to automate rolling my passwords. Ideally keepass expires it, gives me a list and let's me day "go" and be automatically updates them all.
- LoSboccacc 10y agoOnce we had a chance to push openid to internet.... Now that would have been convenient. At least more are working toward google, twitter and facebook oauth, so a majority of services I use has no password at all.
- juliendorra 10y agoInterestingly, the french taxation department used to require you to identify on their website using a certificate, starting in the early 2000s. A few years ago they dropped this requirement and you can now login using just an email and password. The certificate-based identification process was really bad UI-wise so going with passwords probably helped them get more people to interact online instead of via paper forms.
- ohthehugemanate 10y agoThat doesn't make sense - where did the user copy the email/password from, in order to paste it in twice? Somewhere clear text, ergo easy to double check for typos or at least discover them after the fact. If you're worried about someone copy/pasting a typo, you should disable COPY on the field, not paste.
- level3 10y agoIf you've ever run a website that doesn't verify email addresses, you will likely run into this problem. The average person doesn't double check for typos, and they can't discover it after the fact because they didn't notice the typo in the first place, and you won't be able to contact them to inform them. Your suggestion of disabling copy instead of paste may be a better solution, though.
- fattire 10y agoYeah disabling copy makes more sense. I think the scenario is where you have to type your password 2x to avoid typos on a field where you can't see what you've just typed (to avoid shoulder surfers).. the first time the user types the password, then they highlight and ^C and then paste into the second field...
- josteink 10y ago> the first time the user types the password, then they highlight and ^C and then paste into the second field... Except no browser ever allows you to output data (as a clipboard copy-operation is) from a password field. This is not a real scenario.
- dave2000 10y agoI guess it's possible to have an app which lets you click or enter a number and it populates the clipboard with the password. I like the idea of two factor input; enter/select a password on a phone and send it over WiFi to the pc to paste into the field. Does this exist?
- mmariani 10y agoSomewhat related xkcd https://xkcd.com/970/ https://xkcd.com/970/
- cortesoft 10y agoPeople are going to forget their passwords no matter what, so you have to have a system in place for someone not knowing their password. If you have that system in place, it will also work for people who copied a typo in their password. In addition, the whole point of making someone type their password twice when changing it is because you can't see what you are typing in a password field. You also can't copy what is in a password field, so there is no danger of someone copying the typoed password in the normal case. You are only stopping people from using something like a password manager.