The Cobra Effect that is disabling paste on password fields
troyhunt.com
troyhunt.com
Blizzard does the same as Paypal, I noticed: not allowing pasting of passwords when changing passwords, but you can paste it when logging in. Thankfully, I noticed yesterday, Starcraft II allows me to paste the password in-game! That was a nice surprise. Looks like they've given their policy some thought, at least.
The only reason I can think of is perhaps reducing the risk of people not knowing their password when accidentally pasting the wrong thing in the password fields. It's possible that your clipboard contains something else since you copied your password. Which is understandable, but it seems to me like they're replacing one problem with another whereby everybody gets to deal with the new one, whereas the old problem could be circumvented with a password-forgotten function that everybody has anyway.
Yeah, not a big fan of this practice all in all.
Give me the option to view the password I've just entered, then, instead of obfuscating everything beyond comprehension. If I have to type my secure password, there's a good chance I'll introduce a typo anyway.
If presented with two input fields for password & confirm your password, the lazy among us will type the desired new password in the first input box, then copy the contents and paste into the second... if you type it incorrectly in the first box you then have to reset it before you can log in again.
I didn't look at what had been inserted into the clipboard though, it was just the asterisk characters visually displayed in the password field.
It's that old pattern of trying to be 'clever' to work around a problem, which in turn screws over anyone who doesn't actually have that problem, akin to plugging a sideways AC adapter[1] into a horizontal power strip[2]. The sideways AC adapter is a suitable workaround if you don't have a sideways power strip, but if you do it's often much worse (especially if you have two to plug in).
Perhaps LastPass et al should provide a browser extension to prevent this kind of behaviour in the first place (e.g. removing onpaste events from password fields).
[1] http://i.imgur.com/zMSX7K2.jpg [2] http://i.imgur.com/AFfgq9a.jpg
And right there, you've made the wrong assumption that so many have in this thread; the whole point of password managers is that you're not typing anything in, ever. You generate the password, preferably in your password manager, then paste it twice. No possibility of typos.
In fact password keepers should put passwords onto the clipboard into some custom format that the password controls know about so that you have to paste from a tool. And then mandate that the password is at least 256 characters long. That would help move us in the right direction.
At the moment, it seems like copy-paste in passwords is a nice intermediate step between the "password you can remember" era and an era where we have secure keyring managers. In the end, you can imagine that you'd want them stored not on the clipboard (where anything - including Javascript running on a site - can get them easily), but in a secured area of memory, and entered on demand on trusted sites.
Even if the issue has been resolved, few companies seem to be in a hurry to remove parts of their security policy.
I uninstalled the game.
If you force the user to type the password in twice, typos will be spotted immediately and can be fixed.
None of this affects password lockers like LastPass since they can autofill these forms in despite the HTML.
I think it can create problems for some password managers, too: there are at least a few options out there that aren't based on browser extensions at all, so copy/paste is the expected interface.
(Of course there is serious business that won't let you reset a password via email, but you can reset it... the process is simply more involved.)
Why would you ever type in a password when setting up an account? If you've generated a password, you can cut and paste that. Anything "random" you type is likely to be biased.
The overwhelming majority of users do, I'll bet.
As for pasting into the second password field on change-password, maybe they don't want people copying out of the original field and pasting into the second? I'd get that, and the organization-wide costs of password recovery are probably very significant for a company like PayPal. . . . But don't all browsers already disable copying out of password fields?
This is the silliest kind of arms race. Users try to keep ahead of security nonsense, and self-styled security gurus keep on trying to stop them.
You're not just talking about a product, 1Password, you're talking about the whole class of password managers - 1Password, KeePass, lastpass etc. http://lifehacker.com/5944969/which-password-manager-is-the-...
There are many and they all do this. Many of them also offer "auto-type" i.e. simulated keystrokes, as an alternative to paste. It works even when paste is disabled.
On the whole, using a password manager is a very good thing: http://anthonysteele.co.uk/nobody-knows-anything-about-passw... http://www.troyhunt.com/2011/03/only-secure-password-is-one-...