9 ms·
Worse than password rules, are when sites disable the ability to paste in the password in the 'confirm your password' field. Forces users to reduce the 50 chars
by clement_b 5y ago
Worse than password rules, are when sites disable the ability to paste in the password in the 'confirm your password' field. Forces users to reduce the 50 chars crazy password they wanted to set using their preferred password manager with a less secure version.
- CurrentB 5y agohttps://chrome.google.com/webstore/detail/dont-fuck-with-paste/nkgllhigpcljnhoakjkgaieabnkmgdkb https://chrome.google.com/webstore/detail/dont-fuck-with-pas... This has been a greatly appreciated plugin for these scenarios (it's on Firefox as well)
- selfhoster11 5y agoI was going to mention that plugin as well. Its name is explicit with good reason.
- enobrev 5y agoFar too many sites seem to do this with bank account numbers, where you can't paste into the account number OR the confirmation field. Now I need to drag my tab to another window and type it out (twice) and then read and confirm it. If I'm on mobile - forget it. I'm far more likely to get my account number _and_ confirmation wrong if I type them rather than copy/pasting them in from my bank's site.
- U8dcN7vx 5y agoKeepass2Android's keyboard solves this for me.
- GoblinSlayer 5y agoDrag and drop works for me in those cases.
- Hamuko 5y agoI once had to open up my developer console and manually set the field with JavaScript because they didn't want me pasting into the password field. Although the site was also all kinds of broken so it might have actually been an accident that pasting into the field didn't work.
- WorldMaker 5y agoI do this on quite a few sites. Most of the easy ones have an easy to find onpaste event wired in the DOM and it's a simple delete. I feel like there are so few legitimate uses of onpaste and the browser should have an easy override that if I ctrl+v three times in quick succession or something like that it ignores or disables onpaste events. Alternatively, my password manager does have a decent "autotype" tool when all else fails.
- Hamuko 5y agoI find it easier just to select the DOM element for the field and do $0.value = "asd"; instead of finding the onpaste event.
- WorldMaker 5y agoWhen the onpaste is easy to spot it's one key (Delete) after selecting that attribute or event versus a minimum of around 14 give or take keys depending on how good your console autocompletion is. When it is not easy to find, yeah I next try just setting the DOM value.
- slownews45 5y agoNo kidding. Govt websites seem to think this is a positive. Of course, these same folks do the 90 day rotation. Result - everyone writing down passwords on post-it notes next to screens.
- JTbane 5y agoThe TreasuryDirect website requires login with a case-insensitive on-screen keyboard in the page itself. I have no idea why such an idiotic approach would be taken.
- slownews45 5y agoI've used that site - got me to get rid of their inflation protected investments unfortunately! And no cut and paste.
- rav 5y agoI use the following bookmarklet to fix issues like this. It's similar to the browser addon discussed in sibling comments, but without installing a browser addon. Simply create a bookmark named e.g. "Don't mess with paste" with the following URL: javascript:void(document.documentElement.addEventListener('keydown',e=>e.keyCode==9&&e.stopPropagation(),true),document.documentElement.addEventListener('copy',e=>e.stopPropagation(),true),document.documentElement.addEventListener('paste',e=>e.stopPropagation(),true))
- pavon 5y agoOr the site lets your password manager fill the fields, but for some reason their javascript doesn't recognize it and refuses to let you submit because it hasn't verified your password as matching, meeting strength rules, etc. At least in that case deleting and typing just the last character usually fixes it.
- spookthesunset 5y agoProbably some developer who isn’t fully up to speed with what event hooks to use in order to trigger their JavaScript validation rules. And yes it is super annoying. …though not as annoying as sites that don’t let you copy / paste into their login fields.
- ryandrake 5y agoFunny, since the problem of “typing stuff into a text field and submitting it to a web site” was solved over 20 years ago, and without JavaScript. Yet web developers today still manage to try and fail to solve it using code. I guess when your only tool is a hammer…
- atleta 5y agoBesides the browser extensions/addons mentioned above (that sometimes either don't work for me or gets disabled on my machine) I also use/used to use xdotool (on Linux). You can do: `sleep 3 ; xdotool type "yourpassword here"` and then navigate to the field you want to have it typed into.
- antsar 5y agoThankfully, Firefox has an easy way to stop that. about:config dom.event.clipboardevents.enabled = false
- phist_mcgee 5y agoBeware that this may break certain applications that read from your clipboard https://utcc.utoronto.ca/~cks/space/blog/web/FirefoxClipboardeventsIssue https://utcc.utoronto.ca/~cks/space/blog/web/FirefoxClipboar...
- clement_b 5y agoNice! Will try that one.
- banana_giraffe 5y agoI've had this in my AutoHotkey file for a long time now: ; Type in the clipboard ^!v:: MyClip = %clipboard% StringReplace, MyClip, MyClip, `r, , All SendRaw %MyClip% return So I can hit Ctrl-Alt-V and have it type in whatever's in my clipboard. I use it to scrub the text and deal with stupid sites and forms that don't allow paste. I also have a variant that adds a Sleep so I can do the same thing when something like RDP takes control.
- wruza 5y agoArgh, if only AHK used some mainstream scripting language, at least in addition to its leetspeak. I will never learn it by practicing once in a year.
- banana_giraffe 5y agoAgreed. The little snippets in my AHK file are mostly magic incantations to me by now. AHK has a v2 that attempts to clean up its scripting language, but it's been in beta for a long time.