Don't Hijack Browser Keyboard Shortcuts
hypertexthero.com
hypertexthero.com
Let's take the horrible Onswipe themes as another example. They not only break functionality and make the page slower, but also break zooming in and show buttons that pretend to be iOS buttons, but aren't.
I could rant about this for hours. It's all the same basic problem: people trying to redefine/hijack basic browsing functionality. I interpret this as extreme hubris ("I know how to design this better!") or arrogance ("this is how you will view my site, period!").
If you happen to read this and are irritated by the same thing: I was saved by "Findbar Tweak." New essential plugin for me.
Edited to add - how can you stand the lack of next/last arrows in vim?
???
Passwords can be simple copy/pasted from.
Encrypted files can be simply copy/pasted from.
It's also the case that disabling paste doesn't do anything to stop a user from storing their passwords in an unencrypted file.
Here is a workflow:
1) Download keypass.
2) generate random password (however you do that...)
3) copy password into web form.
4) copy passwords into keypass and save.
for logging in:
1) open keypass
2) copy password
3) paste into webform.
Typing the passwords leaves room for errors. Truly random passwords are copied and pasted. Words are typed.
Whether you want to call it a "security flaw" is not obviously an important question.
It could be a security flaw because you discourage using passwords that are truly randomly generated.
Wouldn't using a random password and copy/pasting it imply they are storing it somewhere unsafe?
Edited: you were probably downvoted for using scare quotes.
Anyways, I forgot to remove it again so now my first name is <firstname><oldpassword>.
You can't change your name after your account has been created.
To get around sites that do this, I inspect the HTML and add my password via the value="" attribute on the input element.
When it comes to anti-clipboard, I really hate sites that make you enter your email address twice (Which is retarded anyway; WHY THE FUCK would I not know/check what I am typing?; it's a cleartext field, you might as well have 2 fields for everything up to first name FFS...), then stop you copying emailfield1 to emailfield2. Fortunately, most still let me click and drag from 1 to 2.
The reason email is special is because if that's wrong there's often no good way to fix it (and certainly no way to notify you). Whether that's sufficient motivation is a matter of judgement, but it's clearly different than first name.
* they should be explicitly enabled (i.e. RES for reddit)
* you should be notified if they are changing browser behaviour, and an option to disable shall be provided.
Conflicting interests.
Is there an addon to block shortcut hijacking? I would love that.
Is this the same Blogger that requires JavaScript to view plain text? Or maybe I'm getting it confused with blogspot, I can never keep them all straight. In any case, I don't think it's a coincidence . . .
anyway, well what can be done is - prompt for user agreement to allow these shortcuts, then save it as user preference / cookie / etc..
"An exception may be if your site provides specific functionality such as in a drawing application. Even in this case it is best to provide shortcuts as an option the user has to turn on rather than one that is on by default."
I can think of two ways to solve this: (1) decouple apps from the browser frame or (2) use a special modifier key for app shortcuts (perhaps re-use the Windows key, e.g. Win+Ctrl+S).