Second worst password rule: preventing to paste in the password field.
As seen at The OS X FileVault dialog, PayPal, Blizzard and many more....
As seen at The OS X FileVault dialog, PayPal, Blizzard and many more....
1. Right-click the field, Inspect element.
2. Go to Console tab, type: $0.value = 'mypassword';
$0 is the last selected element: https://developer.chrome.com/devtools/docs/commandline-api
javascript:(function(){var IN,F;IN=document.getElementsByTagName('input');for(var i=0;i<IN.length;i ){F=IN[i];if(F.type.toLowerCase()=='password'){try{F.type='text'}catch(r){var n,Fa;n=document.createElement('input');Fa=F.attributes;for(var ii=0;ii<Fa.length;ii ){var k,knn,knv;k=Fa[ii];knn=k.nodeName;knv=k.nodeValue;if(knn.toLowerCase()!='type'){if(knn!='height'&&knn!='width'&!!knv)n[knn]=knv}};F.parentNode.replaceChild(n,F)}}}})()1. click on the input field. 2. Type document.activeElement.value = 'MyPassword'; into the console.
Browsers should probably not allow that kind of interaction between javascript and the password field.
It's more secure to write it down on a piece of paper, then saving it on your hdd and copy/paste into the password box.