T-mobile password reset does not allow you to type the letter "V"
support.t-mobile.com
support.t-mobile.com
function keyDown(a) {
if (a.keyCode == 86) {
a.preventDefault()
}
}
And that's assigned to onkeydown...Funny enough, elsewhere in their code, they do explicitly check for Ctrl & V/C.
Edit: Apparently I can't reply to the next comment, but keepassx also has the feature that passwords are cleared from the clipboard after 30 seconds.
Gotta love half-assed security measures. :)
"Cut/paste passwords – that’s a stipulation of PCI compliance. We could scrap it, but they ask for it. We have to be PCI compliant on card processing."
I provided as much information as I had available, I do not know the chapter/verse. Apologies if I spread any misinformation, I took this rep at his word.Better yet, if you pasted it into the first field, the second field should become disabled.
This is because usually password fields are not in clear-text but display stars for letters, so you don't know if you accidentally mistyped the password. But if you pasted it in in the first field already, there's no reason you should have to paste it a second time.
It worked, but I couldn't log in to that email for a few days, until I understood, that I've changed my password to
Or Rt-Click -> Paste.
I like my T Mobile service but there's something odd with their backend systems and/or customer service. I logged in to disable their "WebGuard" service that seemed to be blocking pages at random. It required address and social security verification, but I couldn't get it to verify my details.
I called, and the customer service agent hopefully told me that my address didn't exist. I live in the middle of New York, and I've never had this issue before. I can't help but wonder what crazy verification system they're using.
Example?
http://www.quora.com/Orkut/Why-was-Googles-Orkut-built-on-AS...
In fact, I'm pretty amazed that things even work at all. The amount of random connectors and systems is mind boggling.
Some examples: A Tandem system used for nothing BUT ftp from telco switches for call details. Multiple enterprise message buses. Systems with only object files and no source. The list goes on...
Turns out they use a Javascript validator on passwords, not only at creation, but also when you're logging in (beats me as to why). I found a page on their site that doesn't do the check and I can login fine there.
Storing the password in plain text is absolutely inexcusable. I'm an idiot and my passwords are stored PBKDF2/SHA512 - not like it's difficult.
(Though I'm not defending the X keyboard API. Linux input is a nightmare. I especially like the hard-coded list of keys in the kernel, limiting the number of unique keys that any userspace application can address, even though it's perfectly possible to plug in 128 keyboards each with several hundred keys.)
At least that was the state of things about 2 weeks ago
Adobe does the same thing with the horrible license-management selfcare site. Which, as far as I can tell, is some kind of SAP frontend.