Live data from Hacker News

Let them paste passwords (2017)

ncsc.gov.uk

1–10 of 129 posts

Re: Let them paste passwords (2017)

#3
So much of main line security practice is cargo cultism. There is so little use of actual research and data on how compromises actually happen. Somebody just gets the idea something is good for security and it sticks. No rationale needed.

Re: Let them paste passwords (2017)

#4
post #3

So much of main line security practice is cargo cultism. There is so little use of actual research and data on how compromises actually happen. Somebody just gets the idea something is good for security and it sticks. No rationale needed.

There's a lot of dogmatic cargo-culting elsewhere in software too, but it tends to get a lot more force behind it just because it's "for security".

Re: Let them paste passwords (2017)

#8
post #3

So much of main line security practice is cargo cultism. There is so little use of actual research and data on how compromises actually happen. Somebody just gets the idea something is good for security and it sticks. No rationale needed.

If you're pasting passwords into fields from a password manager, even if you paste it into the wrong place there is almost no chance of a real compromise. You have unique passwords everywhere, so a perpetrator would have to guess which of your hundreds of websites it is for.

Re: Let them paste passwords (2017)

#10
post #7

Some password manager browser extensions circumvent password paste prevention, so that's worth looking into.

I've resorted to autohotkey keyboard shortcuts to simulate typing in credentials at times.

When I had to log into this one vpn for work I even used to have it open the 2fa app, click the button to copy the code, open the vpn app, enter all the fields, and log in all from one keyboard shortcut.

Post reply on HN