3 ms·
I would love to see an explicit recommendation of "no disabling paste" in the NIST standard... so that I can contact companies that do so and drive me nuts. T
by ipsin 10y ago
I would love to see an explicit recommendation of "no disabling paste" in the NIST standard... so that I can contact companies that do so and drive me nuts. The article implies that disabling paste would run afoul of the NIST standards, but is there actual language I could point to?
- pluma 10y agoI would sure hope so. I managed to convince a company to allow paste in their login form by tweeting them this article: https://www.troyhunt.com/the-cobra-effect-that-is-disabling/ https://www.troyhunt.com/the-cobra-effect-that-is-disabling/ But I doubt most companies would be this reasonable if they have this level of stupid in their password handling.