If you force the user to type the password in twice, typos will be spotted immediately and can be fixed.
None of this affects password lockers like LastPass since they can autofill these forms in despite the HTML.
If you force the user to type the password in twice, typos will be spotted immediately and can be fixed.
None of this affects password lockers like LastPass since they can autofill these forms in despite the HTML.
(Of course there is serious business that won't let you reset a password via email, but you can reset it... the process is simply more involved.)
Why would you ever type in a password when setting up an account? If you've generated a password, you can cut and paste that. Anything "random" you type is likely to be biased.
The overwhelming majority of users do, I'll bet.
I think it can create problems for some password managers, too: there are at least a few options out there that aren't based on browser extensions at all, so copy/paste is the expected interface.