18 ms·
Let them paste passwords
- tibbon 9y agoAs someone who has used password managers and exceedingly long, impossible to remember and cryptic passwords for years; this quite upsets me when sites prevent it
- graphitezepp 9y agoI can't make any sense whatsoever of it. Does ANY scenario exist where this stops unintended access?
- simias 9y agoI think it's a combination the "Justification 3" in the article (having passwords stick around in the clipboard could be an issue) and maybe the idea by some people that passwords should be memorized and never written down anywhere. Maybe they're worried people will have a "password.txt" in My Documents where they store all their passwords in cleartext. That being said it'd still probably would be more secure than having the same password everywhere like most people seem to do. The road to (UI design) hell is paved with good intentions.
- alanh 9y agoIt’s not like SPP prevents passwords.txt anyway!
- namdnay 9y agoThe only scenario I can accept paste-blocking is double-field password creation. At least one should refuse paste, just to make sure I haven't copied the wrong string. Whilst we're on the topic: I hate stupid input fields that don't ignore whitespace and have a maximum number of characters. So you paste the space-separated number (I'm looking at you IBAN), get an exception because of the spaces, go back and remove them, get another exception, and then realise that the number was truncated due to the field length restriction applied on paste. ARGHHHHHH
- thesuitonym 9y ago>At least one should refuse paste, just to make sure I haven't copied the wrong string. I disagree with this. If you paste a password into both fields, then paste it into your password manager, it doesn't matter if you've copied the wrong thing, because your password manager will still remember it.
- artursapek 9y agoOf course it reduces security. It makes you resort to either 1.) typing it out manually while you can't see if you made a mistake 2.) using developer tools to set the 'value' attribute directly "SPP" discourages use of a password manager. End of story. I also see this pattern used on banking websites for inputs like an account number. This drives me crazy as well for the same reason. The computer can get it right more reliably than my eyes and fingers. Whenever I see a website that blocks paste I immediately assume it's built by incompetent people and trust it with as little as possible.
- sowbug 9y agoI also worry when a site doesn't work with autocomplete. It's rare these days that the developers have actively tried to prevent it from working, but more common that an unnecessarily intricate sign-in flow makes the existence of the password field unrecognizable to the browser. This makes me wonder about the personal security practices of the team that built it -- it's unlikely they typed strong passphrases hundreds of times a day during development -- and whether a secure site could come from such a team.
- Tobani 9y agoThere are a couple of reasons to actively prevent autofill passwords. The only one I have seen for login autofill prevention is when the password is actually a generated token (ala yubikey,etc) and a password manager won't do the right thing by default. There are regulatory bodies that require regular challenge of user identity for approving items as sort of a signature mechanism. This is another time where active thwarting the password manager makes sense. Whether or not the regulation makes sense is an entirely different issue.
- sowbug 9y agoThose are good reasons, and I appreciate when the attribute is used properly in these cases. It's annoying to have to say "no, don't remember this updated password" to my browser every single time I visit certain sites that ask for OTPs that my browser wants to autofill. In the token case, I wonder whether they should have been password fields to begin with. Replacing a 6-digit OTP with asterisks is of questionable benefit, because the shoulder-surfer it thwarts can't reuse the OTP and is really unlikely to swipe it and use it before you do.
- jwl 9y agoI can see some logic behind number 3 of having your password in the clipboard. It could lead to users pasting their password somewhere else where it was not intended. However, if you have malware on your machine that can read your clipboard, it can also simply read your keystrokes anyway.
- MyNameIsFred 9y agoI haven't done Windows development for a long time, but I think that this may be an overstatement, at least on that platform. You need to have cursor focus to receive key events, right? The clipboard, by contrast, can be continually monitored, while playing completely "by the rules", right?
- toyg 9y agoForbidding copypaste is equivalent to forcing one to recite his address and credit card details loudly in public every time he wants to enter his own house. In an age where videosurveillance is trivial to set up, it's just stupid; there is a reason every cash machine/atm asks you to cover the number pad as you type your PIN. If the problem is the risk posed by password vaults and clipboard managers, promote better vaults and better utilities. Personally, I'd love a password vault that could check which application or website I'm pasting to, blocking transmission if it looks wrong. But it's not the website's job to tell me how to manage my secrets.
- discreditable 9y agoOn Chrome you can use "Don't Fuck With Paste" to override these bad forms: https://chrome.google.com/webstore/detail/dont-fuck-with-paste/nkgllhigpcljnhoakjkgaieabnkmgdkb https://chrome.google.com/webstore/detail/dont-fuck-with-pas...
- sillysaurus3 9y agoI was hoping this would also prevent websites from messing with the input to the clipboard. It's a bit annoying to copy a sentence from a website only to have "Read more on XYZ!" appended to it.
- thebouv 9y agoFork the Don't Fuck with paste code and add that feature (or use it as an example to make your "Don't fuck with copy" extension). https://github.com/jswanner/DontFuckWithPaste https://github.com/jswanner/DontFuckWithPaste I hate sites that do that (or prevent right-click as if that somehow secures their code).
- majewsky 9y agoI'd actually like an extension along the lines of "This is not Google Docs, for fuck's sake", that just disables all these APIs that are only ever useful with rich apps, but not with content-heavy websites, for example: - copy/paste hijacking - sensor access: microphone, camera, GPS, etc. Maybe even go further and introduce some sort of rate-limiting for - XHR requests - relayout events to save power and data.
- artursapek 9y agoIncidentally, what are these APIs? I am building a rich content app (SVG editor) and have been starting to think about what copy + paste will look like.
- akubera 9y ago
- dmh2000 9y ago"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak
- simias 9y agoSo by definition your password manager master key is weak? That's an interesting paradox!
- BoorishBears 9y agoIt's remembering one password vs X, and it is pretty hard to remember in my case, almost 4 months into using this password and I still struggle to type it in correctly sometimes
- simias 9y agoYeah I was just kidding, I see what the parent meant. Now I use a hardware token (yubikey) to store my PGP key so I can use a relatively weak PIN code on it (since you need to have physical access to the device to use it and you only have 3 attempts before it locks up). It's a pretty good quality of life improvement.
- majewsky 9y ago> you only have 3 attempts before it locks up Then you better don't use it when you're fatigued or drunk. I nearly locked my SIM card once by not realizing until the third attempt that my phone was asking for the SIM card PIN rather than my lockscreen PIN.
- simias 9y agoThere's also an "admin PIN" that can be used to unlock the key if something goes wrong. It's more complicated than my regular PIN and I didn't memorize it so that should be enough as a defensive measure against drunk me. Well, unless I'm silly enough to try and bruteforce that PIN as well, after 3 failures I'd be left with an expensive piece of plastic... Fortunately I'm rarely that drunk. EDIT: Actually as the sibling comment points out you can still reset the token even if you mess up the admin PIN. So at least you won't "brick" your token completely.
- hammock 9y agoEveryone's talking about password at sign-in or credit card numbers but that's not the only use case for paste restriction. The more common place I've seen it is email address confirmation (or PW confirmation), which while probably unnecessary, is not the worst thing in the world. You are retyping an address that's displayed in the field above. Less intrusive than a captcha.
- tomku 9y agoBlocking pasting in a password confirmation input accomplishes nothing because you're already blocked from copying the contents of the first password input anyways. All it does is inconvenience people who use password managers.
- deleted 9y ago[deleted]
- alvarosevilla95 9y agoPlease correct me if I'm wrong, as this is all conjecture. I feel passwords used to be thought of as a combination of characters that you keep in your head, and should only leave your head when being entered in a password field. Preventing paste discourages storing your password in a file called passwords.txt, and accidentally pasting it somewhere else as well. Of course, we now understand passwords should have some qualities (larger alphabet, avoid common words/phrases as your passwords) which go against ease of remembering, so we now use passwords managers and other tools. So this behaviour is probably and old common practice that most people used without knowing why and that's why we still see it even if its outdated and harms security in the end
- Santosh83 9y agoCould be, but it's flawed reasoning anyway. Preventing copy/paste won't prevent people from storing their passwords in passwords.txt. Nobody other than those who use very simple, high risk passwords can remember them all. It has to be stored somewhere. Preventing copy/paste seems like a completely useless step (security wise) that only causes unnecessary bother.
- WorldMaker 9y agoAlso, depending on threat model, a passwords.txt clear text file can be perfectly cromulent security that is better than many alternatives (password reuse, weak passwords). It's not going to stop people with physical access to your machine or attackers specifically targeting you looking for weaknesses in your documents. But vulnerability to some threat models is not vulnerability to all of them and it's okay to take a security stance with known vulnerabilities. Similarly with Post-It Notes and physical written Notebooks of passwords. If your threat model isn't concerned about people with physical access to those notes, and you are comfortable with the physical security of those notes, that can be perfectly acceptable for you, and an overall better security stance from bad passwords. "Don't write down your passwords", has always been bad advice, from that perspective. "If you write down your passwords, keep them safe" is slightly more accurate.
- raesene6 9y ago
- hashkb 9y agoBank info pasting is more annoying, more common, and just as stupid.
- SurrealSoul 9y agoAssuming you are creating an account, UN: Hello PW: World123 My largest issue is that its extremely possible to fat-finger your UN to be Hellow, and its extremely easy to see and fix that mistake. However since passwords are hidden its hard to see ######## is actually Worls123. Now your new account has essentially a one-time login because you have no idea what your password is. Typing it out again, ensures you catch your mistake
- hammock 9y agoOP isn't talking about password confirmation fields, which are similar to my other comment about email confirmation fields. They are talking about sign-in forms.
- noir_lord 9y agoI hate hidden passwords, it's stupid. I'd notice someone shoulder surfing so I'd prefer if they wheren't starred out by default with starring out as an option if I do have people around.
- blauditore 9y agoWhat about e.g. sharing a screen during a presentation?
- sowbug 9y agoSlightly off-topic: why didn't client-side certificates ever become a thing?
- Santosh83 9y agoPasswords were already almost universal even before ANY encryption, during the early days of the WWW and before that too.
- diggernet 9y agoEncryption has been around longer than computers.
- acdha 9y agoThat's technically true but irrelevant: on the web, SSL came well after the initial wave of adoption and U.S. companies were restricted by law[1] from exporting strong encryption to people outside of the United States. It took awhile to get programs updated and for years it was common to see separate versions (or even third-party patch trees) on download pages. All of that meant that someone launching a service couldn't assume that their users’ software supported encryption at all or securely for years. Coupled with the previously mentioned horrible user experience and cost of certificates, that really killed the idea since the password experience was both easier and far more familiar. 1. https://en.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States#PC_era https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
- npongratz 9y agoSome old discussion here: https://news.ycombinator.com/item?id=6732110 https://news.ycombinator.com/item?id=6732110
- dfox 9y agoThere are two main reasons: 1) In the beginning the whole X.509/PKCS PKI mechanism was seen as something that came out of X.500 and other telco stuff, is centralized, complex and expensive (all of these things are in fact true for the originally envisioned usage) and thus irrelevant for decentralized internet. (for example, the L for "Lightweight" in "LDAP" essentially means that it uses passwords instead of client side certificates) 2) The UX in early SSL capable browsers for client-side certificates was horrible (In Netscape the whole SSL configuration was in completely separate dialog from browser settings, which was incredibly complex. IE uses SSL implementation from windows which is also used for lots of other things and has centralized configuration and also even today creates confusing dialogs when site requests client certificate). It's somewhat ironic that various ActiveX/Java based replacements of this horrible UX are in fact often even more unusable.
- ytch 9y agoI also hate websites that force users use virtual keyboard to enter password.
- matthewbadeau 9y agoThis is supposed to prevent keylogging.. but I think anything with that amount of access to your PC can tap into the browser to read the request before it's sent. So, probably not as good as it sounds.
- ytch 9y agoYes, and it may also screenshoting the pixels around where mouse clicks, so I don't think it can prevent keylooger. OTP is better solution.
- Cthulhu_ 9y agoIt would prevent physical keyloggers (small dongles in between keyboard and computer) and possibly even RF keylogging, but yeah, it's a false sense of security.
- EdgarVerona 9y agoJust yesterday, I ran into a site that was doing this for the first time in years. It annoyed me to the point where I used the console to override it and allow pasting again. Password managers are a thing. Please don't force me to type out 32 random symbols twice while I sign up for your service.
- bikamonki 9y agoI've pasted my ultra long pwd in the username field and hit enter. It happened more than once on logins where the form is split into two steps (I am talking to you Google). Why do they split the u/p fields into two steps? Does it add security? Better UX?
- Santosh83 9y agoThe first login page allows you to choose from multiple accounts. But yes, this could just as easily have been done through browser auto complete, but doing it this way means Google can track/link your multiple accounts.
- dredmorbius 9y agoReference on this?
- Khol 9y agoAs irritating as this is my bank's app which implements its own soft keyboard, so not only can I not paste my (complex) banking password, the password manager doesn't recognise it as an input. Since I can't have the password visible in the password manager on the phone at the same time as the login prompt in the app, this means that I can only use the bank app if I'm 1) next to another device I can get that password on or 2) if I write the password down on something.
- TheCowboy 9y agoIssues like this (including SPP) have forced me to start using sequences of randomly generated words/phonetics for specific websites. It's not ideal, but it allows me to function.
- egypturnash 9y agoThis sounds like a reason to consider switching to a new bank. Or a credit union.
- graton 9y agoI know that Battle.net does this :( I went to change my password and I couldn't paste the new one I had generated. Motivated me to install a simple Greasemonkey script to override that.
- maxxxxx 9y agoThis whole discussion is a good example for everything that's wrong with computer security. Instead of coming up with solutions that make it easy for people to follow good practices the "experts" make it even more cumbersome. Most people just want to use the computer and not think about security.
- sanderjd 9y agoYour comment would be interesting if it brought some ideas to the table. Lots of people work hard to come up with ideas that strike a good balance on the really difficult trade off between security and convenience. Comments like yours that seem to imply this should be really easy, but don't provide any ideas, aren't very helpful.
- maxxxxx 9y agoIf I had a good idea I would have provided it. I wish I had one. What I am saying is that from a regular user's perspective there is no viable way to do it right and we shouldn't be surprised if people follow bad practices. We can't just tell people to: - don't write down passowrds - have unique strong passwords for dozens of sites - always type them in It's not going to happen.
- acdha 9y agoYou're cherry-picking pretty heavily: there's a lot of cargo-culted password advice but the current push for user-friendlier password management practices and fundamental model changes (e.g. two-factor with U2F) has been lead by security experts who have, for many years, been loudly reminding everyone that usability is a security requirement rather than an inherent conflict.
- maxxxxx 9y agoYou are probably right about cherry picking. I know a lot of experts are aware of the problems but from an end user perspective security usability is still horrible and inconsistent.
- xir78 9y agoOnly argument I can think of for preventing it in is maybe it makes it harder for bots in some cases. The QQ messenger blocks pasting passwords on iOS I suspect for this reason, perhaps there are teams of people guessing passwords and manually typing them in like gold farming.
- rcthompson 9y agoIf you're on Mac OS, there's a nice little app I use to bypass almost any mechanism of preventing pasting. It simply uses a virtual keyboard to type out the contents of your clipboard. http://dae.me/blog/1741/ http://dae.me/blog/1741/
- deleted 9y ago[deleted]
- raesene6 9y agoI'm very glad to see this advice for the NCSC, they have been taking a good practical stance on many security issues and helping to provide weight to more pragmatic approaches. I've never actually managed to find out where the idea of websites banning copy/paste came from. Presumably it's been as a result of security audits, but I can't find any security people who would argue that it's a good idea...
- dragonwriter 9y agoIf you are pasting passwords, you are really using an ad hoc third-party SSO authentication provider (which may or may not also use the equivalent of 2FA) via a manual token-exhange mechanism. Better than allowing pasting passwords, just support OpenID or some similar federated authentication solution, which does the same thing without manual token exchange and the attendant opportunities for errors. You might want to allow paste, too, but it's the clumsy solution.
- sanderjd 9y agoThink of it this way: passwords are a more standard API than OpenID. Since passwords are the standard, they are "implemented" by all your clients. That cannot be said for OpenID.
- dragonwriter 9y agoI'm not suggesting "don't implement passwords" (which are first-party authentication) or "don't support password pasting" (which mainly supports ad hoc third-party authentication with a manual token exchange), but if you are actively choosing to support pasting (and, thus, third-party SSO with a clumsy UI), you should also strongly consider supporting third-party authentication with a decent UI.
- sanderjd 9y agoThe password manager solution is, if you'll allow me to strain your analogy a bit, "second-party SSO". That is, it's SSO that I, the user, manage however I prefer. Password pasting is an extensible API for achieving that. But we don't disagree, folks should definitely implement things like OpenID.
- lmm 9y agoPasswords offer a much more consistent UX across sites and leave the user much more in control. Plain text is a lowest common denominator but that allows a lot of tools to work with it that can't handle fancier models.
- 9y ago
- _jal 9y agoIn general, more and more sites encourage me to just leave Javascript turned off all the time. If they break, screw them, I'll go elsewhere. The only sites "sticky" enough to make me put up with it are financial, and that's only because they all suck so changing solves nothing. 'Missing out' on Angular sites hasn't left me feel like I'm missing anything in my life. This ties in to the discussion of Craig's List the other day. It is so refreshing to use a site that doesn't try to be clever. I understand if people find it ugly, but I don't - simple is good, and I don't care if sites follow whatever design trend is hot this week. Usability is far more important.
- hn_throwaway_99 9y ago> If they break, screw them, I'll go elsewhere. I think that option is going to greatly constrain where you are able to go on the web. The vast majority of ecommerce sites I visit will break with JS completely turned off.
- jehna1 9y agoI've been using Internet for almost two years with JS disabled by default. My experience is, that while ecommerce sites may break, most of them are quite usable even without JS. Most good blogs work just fine. And the ones that don't I usually don't bother reading.
- devrandomguy 9y agoOTOH, these "universal" web apps/sites can work quite well without JS. As long as the developer isn't doing silly things like using <button> as a link, or using an anchor to submit a form. At one point, I built a sortable filterable table for an admin UI, using React. One of the admins was a "no js" guy, and he thanked me for building the whole thing in functional HTML. Up until that point, I had no idea that the admin side of the system was even usable without JS; that was just a natural consequence of optimizing for SEO and load speed (server side rendering, URL representation for all significant state).
- _jal 9y agoFar fewer than you'd think, at least among the ecommerce shops I buy stuff from. And those are mostly the huge shops, which are mostly interchangeable as far as I'm concerned.
- majewsky 9y agoMy mind, upon reading the submission title: "Your majesty! The country people don't have any usernames!" - "Then let them paste passwords!" (https://en.wikipedia.org/wiki/Let_them_eat_cake https://en.wikipedia.org/wiki/Let_them_eat_cake)
- liveoneggs 9y agoI see passwords pasted into chatrooms constantly and they are often of randomly-generated form. Password manages are also, apparently, not immune to their own security issues.
- epistasis 9y agoThe nice thing about that is it's just one site's security token to change! Compromising that single password doesn't compromise all logins, just the one. Whereas if you reuse a password on multiple sites, and one of those sites is compromised, all of the rest of your logins are compromised.
- coldpizza 9y agoSo the main complaint about SPP is that it screws password managers, but then there's this: > Most password managers erase the clipboard as soon as they have pasted your password into the website, and some avoid the clipboard completely by typing in the password with a 'virtual keyboard' instead. Isn't the latter approach much safer? If so, shouldn't it be the de facto standard since it prevents "clipboard stealing" and also removes the issue of not being able to paste content into an SPP form input?
- jhasse 9y agoAllowing apps to create virtual keyboards with which they may manipulate all other apps might not be a good idea. That's why it won't work with Wayland for example.
- ben_jones 9y agoI mean your password manager already has all your passwords. The argument can be made that you can trust the man who already has a knife to your throat.
- jhasse 9y agoTrue, I trust my password manager. But having the ability to create virtual keyboards at all might be a risk for the apps I don't trust.
- arunc 9y agoAll I can say is use keepass. Just remember one crazy long master password for the database and change it regularly. Or use a combination of password and key file. > Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'. Difficult to remember and easy to forget passwords will be auto generated. In fact I encountered few websites that didn't accept long passwords. > Justification 3: 'Passwords would hang around in the clipboard' Only for 12 seconds after which keepass will clear the clipboard.
- jomkr 9y agoThere is a subtle valid use-case. On "change your password" screens, you don't want the second "confirm password" field to be pastle-able to stop this scenario. 1) User tries to type "mypassword" but enters "mypasswor" instead. 2) User copy-pastes "mypasswor" into "confirm password field" 3) User hits "submit". Now when the user tries to login with "mypassword" it fails.
- teej 9y agoCan't the user just reset their password again?
- city41 9y agoThat is true, and a valid point. But preventing pasting here will still discourage the use of password managers. I ask my password manager for a new, very long, and very difficult to type password. I paste it twice. It's a shame that password managers are mostly used by tech savvy people, as they are probably the most secure way to deal with passwords we've come up with so far.
- PUSH_AX 9y agoIf the input field is of type password the browser won't allow you to copy from it anyway. Pasting should still be allowed.
- crazygringo 9y agoBut you can't copy from password fields, so that won't actually work. When changing your password, if you're pasting at all, it's from another (presumably correct) source -- so pasting is fine, whether once or twice.
- deleted 9y ago[deleted]
- jeffhuys 9y agoI thought it's not possible to COPY from a password field?
- thechriswalker 9y ago
- jomkr 9y agoThere is a subtle valid use-case. On "change your password" screens, you don't want the second "confirm password" field to be pastle-able to stop this scenario. 1) User tries to type "mypassword" but enters "mypasswor" instead. 2) User copy-pastes "mypasswor" into "confirm password field" 3) User hits "submit". Now when the user tries to login with "mypassword" it fails.
- davotoula 9y agoPreventing copy/paste is a pet peeve of mine. Hey websites, you are breaking the browser/os functionality! Another annoyance is having to enter 2nd,4th,7th etc letter of the password using a dropdown. ARrrgh.
- inian 9y agoI had filed an intervention to prevent websites from disabling the paste functionality in password fields - https://github.com/WICG/interventions/issues/41 https://github.com/WICG/interventions/issues/41
- probablycarrots 9y agoThere is another version of SPP being done by the Wells Fargo Commercial Electronic Office site, and probably others. https://wellsoffice.wellsfargo.com https://wellsoffice.wellsfargo.com It does allow you to paste into the login fields, but you cannot submit your login credentials this way because the "Sign On" button is greyed out until you've actually typed in each field. I let my password manager fill the fields, then I manually delete and re-type the last character from each of the 3 fields.
- jcoffland 9y agoThe Wells Fargo CEO portal makes me change my password every 90 days, won't let me paste and accepts some special characters but not others. How is it that a bank can get it so wrong?
- ryanisnan 9y agoJ2EE people, man... J2EE people.
- nathancahill 9y agoIf you use Quicksilver on Mac, you can virtually type the text to get around the paste limitation. [text input] -> [Type Text]
- nofunsir 9y agoyubikeys help here a little bit.
- hobarrera 9y agoFWIW, middle-click pasting (PRIMARY) doesn't seem to be inhibited anywhere (maybe this technique only invalidates the CLIPBOARD pasting?).
- phkahler 9y agoI find the issue around clipboard security a bit disturbing. No program should be able to access the clipboard at will, it should only get the data there if the user pastes it in the application. This is a bit harder at the API level, but I think a good environment would do this right. It's like the security holes in X that are being closed with Wayland.
- defined 9y agoIf it didn't point crackers to these sites, I would love to call out all the sites that do incredibly misguided things such as: - Allow you to paste passwords into their smartphone app, but not into their web site being accessed from the same device. - When entering new passwords, limit the password length but not tell you what the limit is ("password is too long"), so you have to reduce it 1 character at a time and keep trying. - (Mentioned elsewhere in this post) Limit the special characters to some inexplicable subset like !@#$, so you have to edit your generated random password and replace the non-compliant characters with ones from their subset. - Limit password lengths to (say) 20 characters, allow you to enter a new 20 character password, but only store the first 19 characters so you get an invalid password error when you subsequently log in! I figured it out because I knew I was pasting the correct password, so I just thought, "Hmm, UI team != DB team..." and tried one less character. Bingo. This happened to me with an old version of (IIRC) a Bank of America iOS online banking app (I am not concerned about mentioning a name here because it's been fixed since then). - Limit your password to something really short like 10 alphanumerics. - Require password entry for (say) iCloud before you can get into your password manager, forcing you either to pull up the password on another device and painstakingly enter by hand a 30 character random string, including many special characters, and not letting you see the password (only the last character, for a second). This is so unpleasant that I am sure many people would just change the password to their dog's name or something.
- marmshallow 9y agoSome of these are actual reasons why I don't use password managers. I'd rather have the convenience of being able to quickly type in a password that I can easily remember than have to worry about which special characters I'm using or manually typing in an insane hash.
- deathanatos 9y ago> Justification 3: 'Passwords would hang around in the clipboard' Password managers could wipe the clipboard, if it still contains the password, after a defined amount of time, such as 60 seconds. (If you think that's "confusing", show a notification that explains the behavior; "clipboard wiped" or something.)
- mderazon 9y agoI don't care much when it happens on a website, because I can bypass that easily, but it's enraging when I see this practice in mobile apps. For example, my bank's app don't let you paste passwords. I have a strong random password which basically means I can't access it from my phone...
- apostacy 9y agoChase.com is one of the worst. The desktop version of the site does all sorts of browser fingerprinting with javascript. It does things like tries opening up websockets to random local ports, and stuff like that. I had to just throw up my hands and do all of my access to chase.com through a sandboxed browser profile, where I could automate logins.
- JadeNB 9y ago> Chase.com is one of the worst. The desktop version of the site does all sorts of browser fingerprinting with javascript. It does things like tries opening up websockets to random local ports, and stuff like that. I'm not fond of this, but what does it have to do with passwords? I (reluctantly) use Chase's online banking on the desktop, and it lets me paste passwords.
- pc2g4d 9y agoHere's another weird restriction: password length limits. I've had websites tell me I can't use more than 8 or 16 characters. Even if they let me use a thousand characters that's just going to get hashed to the same length anyway, right? Even worse: sites that silently truncate your pasted password to the maximum length. When all you see is those little dots and the password is wider than the text field, it's very difficult or perhaps even impossible to tell how many characters were successfully pasted. And obviously truncation sets you up for disaster when you try to log in using your saved password and it just doesn't work.
- tdeck 9y ago> Even if they let me use a thousand characters that's just going to get hashed to the same length anyway, right? That assumes they're not storing your password in a VARCHAR(16) field, which is what I always assume when I see a max password length restriction like this. Or perhaps they're using the ridiculous LANMan hash algorithm [1]. [1]: https://en.wikipedia.org/wiki/LAN_Manager#LM_hash_details https://en.wikipedia.org/wiki/LAN_Manager#LM_hash_details
- agentgt 9y agoI'm somewhat guilty of pushing the don't copy'n paste passwords (not the actual input limitation) and the reason why is because several of our guys at work have actually accidentally pasted passwords into Slack/Skype windows. For what its worth I did write a small utility to make it easy to create memorable passwords using a master password: https://github.com/agentgt/ezpwdgen https://github.com/agentgt/ezpwdgen It uses the Emoji word database to help you remember passwords.
- intrasight 9y agoAnother reason SPP is less secure is keyloggers. I remember reading an article by someone that discussed this. When he visited China, he always entered passwords by copying and pasting from a secured thumb drive as this would defeat keyloggers. He mentioned that unfortunately some sites stupidly prevent this.
- crystaln 9y agoUntil password managers are ubiquitously integrated with mobile apps, we are forced to use the clipboard to transfer passwords. Unfortunately, any app can access the clipboard, revealing passwords. Copying passwords from 1password always feels dirty for this reason, and unfortunately I don't have a good solution to this problem.
- kobayashi 9y agoI agree with the premise. Though, there's one more issue/potential reason not to endorse people using the clipboard for passwords, and it's not that malware will grab them from the clipboard. It's that many non-malicious programs will regularly query the clipboard for legitimate reasons, but what they do with that data may be insecure. For example, think of how Pocket checks the macOS/iOS clipboard for URLs to add to the Pocket list.
- daxorid 9y agoGood, but bear in mind that the Xorg clipboard is, in many cases, readable by arbitrary applications. If you can run Wayland, do it. If for no other reason, this.
- waffl 9y agoThis is an incredibly frustrating thing with the way OS X handles encrypted disk images as well. Needing to share confidential documents with coworkers, we were hoping to store them in an encrypted disk image. (GPG proved way too complex for anyone to adopt) Of course, the standard OS X GUI prevents you from pasting a password when mounting, which of course led to coworkers resorting to short, easy to type, easy to remember (and easy to crack) passwords. The best solution I found was to mount via the command line but that definitely wasn't an option for any coworker unfamiliar with the terminal. https://apple.stackexchange.com/questions/42257/how-can-i-mount-an-encrypted-disk-from-the-command-line https://apple.stackexchange.com/questions/42257/how-can-i-mo... Also while this may be ultra paranoid, I really don't like typing passwords in public places where endless he cameras can record my screen and keystrokes.
- joantune 9y agoYes!! Ditto on the weirdness of not allowing to paste from the clipboard to decrypt a hard drive on OS X. It's like it's on purpose to make you save the password on the keychain or to make it more predictable somehow. I think that's either a very bad decision or evidence of NSA/CIA infiltration/influencing of Apple's software
- deleted 9y ago[deleted]
- joantune 9y agoMay i also say that the 'feature' of not allowing clipboard pasting on the Mac Os X to decrypt a hard drive is one of the most conspicuous interface decisions that I have ever seen
- joveian 9y agoIMO, sites should generate a >20 character random base64 password as a form prefill on the registration form, which hopefully would cause browsers to remember it (don't actually let the user change this). Provide "show password" and "copy password" options for those who need to write it down for use on other machines or want to export it to a non-browser based password manager or sync tool. Encourage users to have a master password for the browser password storage. Also, many sites should have an easy email based login.
- sengork 9y agoFor macOS users, at least, there is another option: select text and drag and drop it from password manager text field to a website input field. From what I gather this should use IPC between applications, rather than the clipboard itself.
- libeclipse 9y ago> Justification 1: 'Password pasting allows brute force attacks' This really pisses me off every time I see it. JavaScript is client-side code. If the attacker you're protecting against can't trivially bypass this bullshit "security" feature in three seconds, then he/she is not something you should be concerned about. Attackers like that probably have other skills like counting to 5 with a 60% accuracy, and pointing out their own nose with a 40% accuracy. (Just like you do if you have this on your website.)