Live data from Hacker News

Let them paste passwords

ncsc.gov.uk

11–20 of 376 posts

Re: Let them paste passwords

#11
Everyone's talking about password at sign-in or credit card numbers but that's not the only use case for paste restriction.

The more common place I've seen it is email address confirmation (or PW confirmation), which while probably unnecessary, is not the worst thing in the world. You are retyping an address that's displayed in the field above. Less intrusive than a captcha.

Re: Let them paste passwords

#12
post #2

As someone who has used password managers and exceedingly long, impossible to remember and cryptic passwords for years; this quite upsets me when sites prevent it

I can't make any sense whatsoever of it. Does ANY scenario exist where this stops unintended access?

I think it's a combination the "Justification 3" in the article (having passwords stick around in the clipboard could be an issue) and maybe the idea by some people that passwords should be memorized and never written down anywhere.

Maybe they're worried people will have a "password.txt" in My Documents where they store all their passwords in cleartext. That being said it'd still probably would be more secure than having the same password everywhere like most people seem to do.

The road to (UI design) hell is paved with good intentions.

Re: Let them paste passwords

#13
Please correct me if I'm wrong, as this is all conjecture.

I feel passwords used to be thought of as a combination of characters that you keep in your head, and should only leave your head when being entered in a password field. Preventing paste discourages storing your password in a file called passwords.txt, and accidentally pasting it somewhere else as well.

Of course, we now understand passwords should have some qualities (larger alphabet, avoid common words/phrases as your passwords) which go against ease of remembering, so we now use passwords managers and other tools.

So this behaviour is probably and old common practice that most people used without knowing why and that's why we still see it even if its outdated and harms security in the end

Re: Let them paste passwords

#15
post #8

"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak

So by definition your password manager master key is weak? That's an interesting paradox!

Re: Let them paste passwords

#16
Assuming you are creating an account, UN: Hello PW: World123

My largest issue is that its extremely possible to fat-finger your UN to be Hellow, and its extremely easy to see and fix that mistake.

However since passwords are hidden its hard to see ######## is actually Worls123. Now your new account has essentially a one-time login because you have no idea what your password is. Typing it out again, ensures you catch your mistake

Re: Let them paste passwords

#18

Assuming you are creating an account, UN: Hello PW: World123 My largest issue is that its extremely possible to fat-finger your UN to be Hellow, and its extremely easy to see and fix that mistake. However since passwords are hidden its hard to see ######## is actually Worls123. Now your new account has essentially a one-time login because you have no idea what your password is. Typing it out again, ensures you catch…

OP isn't talking about password confirmation fields, which are similar to my other comment about email confirmation fields. They are talking about sign-in forms.

Re: Let them paste passwords

#20
post #15
post #8

"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak

So by definition your password manager master key is weak? That's an interesting paradox!

It's remembering one password vs X, and it is pretty hard to remember in my case, almost 4 months into using this password and I still struggle to type it in correctly sometimes
Post reply on HN