2 ms·
The opposite should be true: you should only be allowed to paste passwords. In fact password keepers should put passwords onto the clipboard into some custom f
by justncase80 12y ago
The opposite should be true: you should only be allowed to paste passwords.
In fact password keepers should put passwords onto the clipboard into some custom format that the password controls know about so that you have to paste from a tool. And then mandate that the password is at least 256 characters long. That would help move us in the right direction.
- x1798DE 12y agoWhile I'm hoping this is a hyperbolic suggestion, it's almost certainly a bad idea to use the clipboard for this sort of thing, because none of that is sandboxed properly, and creating a special format that says, "I'M A PASSWORD" sounds to me like designing an API for malware authors, frankly. At the moment, it seems like copy-paste in passwords is a nice intermediate step between the "password you can remember" era and an era where we have secure keyring managers. In the end, you can imagine that you'd want them stored not on the clipboard (where anything - including Javascript running on a site - can get them easily), but in a secured area of memory, and entered on demand on trusted sites.