4 ms·
As someone running a user-facing site, you cannot control whether your users use password managers. So what's your solution? Just disregard the segment of your
by level3 10y ago
As someone running a user-facing site, you cannot control whether your users use password managers. So what's your solution? Just disregard the segment of your users who don't use password managers? That's a tradeoff that you might not want to make, depending on your business.
Also, if you're someone who uses a password manager, does disabling pasting really make you less secure? I assume you're still generating passwords; you just have to retype them. So maybe less convenient, but less secure is kind of a stretch. (By the way, I personally use KeePass, and I generally use auto-type instead of pasting, so I'm not inconvenienced at all.)
- raldi 10y ago> So what's your solution? Allow pasted passwords if they meet a very high password-quality heuristic; deny them if they seem too guessable.
- level3 10y agoHow is that a solution to the problem of user error (i.e. mistyping)? Are you making an implicit assumption about password manager use and mistyping, that somehow your heuristic will be able to differentiate? That seems like a lot of work for something that may be prone to mistakes, while also delivering an inconsistent user experience, for the sake of some (unstated) assumptions about security that may not be founded.
- morgante 10y agoIt actually makes a lot of sense. People will almost never manually type out high security (>20 random characters) passwords themselves. So if someone enters a high entropy password, you can fairly confident that mistyping is not an issue.
- level3 10y agoI'm not quit convinced about that. 1) Aren't there people using generators like Diceware that don't do the password management part? 2) The industry's definition of "high security" is constantly changing. Password strength measurement makes assumptions about what is and isn't guessable, and a lot of that depends on what techniques the common brute-force crackers are employing. So finding the right heuristic is also problematic.
- morgante 10y ago> 1) Aren't there people using generators like Diceware that don't do the password management part? I'm not sure they're actually that common. Moreover, if someone is sophisticated enough to use a password generator I assume they have some sort of system for ensuring integrity. Also, if you're worried about someone changing their password to something they don't know, simply force a relogin and have effective password reset mechanisms. > 2) The industry's definition of "high security" is constantly changing. Industry might be getting more serious about encouraging higher security passwords, but standards for high security passwords haven't really changed much. People are just becoming less tolerant of low-security ones. In terms of estimating security, you can use something like https://github.com/dropbox/zxcvbn https://github.com/dropbox/zxcvbn which does a pretty good job of evaluating entropy and resistance to brute force attacks. Ultimately, a password with sufficient entropy will be resistant to any brute force cracker.
- Dylan16807 10y agoThe nice thing about password generators is that you can have a huge margin of strength for free. Keepass defaults to 119 bit passwords. Require 100 estimated bits and you'll blow manual passwords out of the water.
- simbalion 10y agothere is no solution for user error. give up on that dream right away. isolate the users so they cannot destroy your system when they get hacked, because they will always get hacked.
- morgante 10y ago> Just disregard the segment of your users who don't use password managers? No, I recognize that most users probably don't use password managers. But I'm not convinced that disabling pasting helps much. For one thing, I don't actually think it's that common for someone to copy a mistyped password. Browsers disable copying from password fields, so they would have to type it in a third place and copy it into the fields from there. Most users are not sophisticated enough to do that. > Also, if you're someone who uses a password manager, does disabling pasting really make you less secure? It directly encourages people to use less secure passwords. If I try to manually retype a 50 character password myself, I'm very likely to make an error. This isn't theoretical—I've often purposefully lowered the complexity of passwords for sites with these kind of arbitrary restrictions. It's too bad 1Password doesn't have an auto-type feature.
- level3 10y agoThat's a fair point that in general, password fields aren't copyable. So I do think that retyping passwords has value, but disabling pasting may have questionable value. (In my experience, disabling pasting on email confirmation fields does reduce the rate of error there, since lots of people copy-paste)
- ry_ry 10y agoYou can get/set HTMLInputElement.value on [type="password"] anyway so if you wanted to shim the PW field copy/paste functionality back, you could just create a bookmarklet or something. Edit, threw an example together. Ignore the horrible code ;P Http://jsfiddle.net/6gc2d6hb Type in one of the PW fields then double-click it. Doesn't overwrite populated PW fields.
- happyslobro 10y agoAnd once again, we find ourselves inspecting elements to fix someone's brilliant idea.
- ry_ry 10y agoTrue enough - the open nature of the client makes a joke of so many do-called security measures implemented there.
- pwg 10y ago> Just disregard the segment of your users who don't use password managers? No. But, consider that the segment of your users who don't use password managers is also very likely 100% intersecting with the segment of your users who do not ever attempt to paste a password into a password field. So by blocking paste you have zero effect on the users you wish would improve their password practices, and a 100% negative effect on the set of users who are creating and using secure passwords.
- thaumasiotes 10y ago> But, consider that the segment of your users who don't use password managers is also very likely 100% intersecting with the segment of your users who do not ever attempt to paste a password into a password field. I guarantee you are wrong about this. For example, a lot of people receive passwords via email, and then paste them in.
- ams6110 10y agoI think I am slightly dyslexic, and have immense difficulty correcly transcribing a random string that is more than about 8 characters especially if it has numbers and random non-alpha characters. Logins that don't allow pasting the password often cause me to lock myself out due to repeated errors typing the password.