Live data from Hacker News

Let them paste passwords (2017)

ncsc.gov.uk

11–20 of 129 posts

Re: Let them paste passwords (2017)

#11
Seems a plausible concern that malware on the PC can access the clipboard, so they discourage copying their password into clipboard. But intercepting keystrokes to another program (at least in Windows) doesn't require any special permissions either. Would the concern more be background web tabs (cross-site) accessing the global clipboard? Vaguely recall that was possible a long time ago but likely locked down now.

Re: Let them paste passwords (2017)

#12
post #11

Seems a plausible concern that malware on the PC can access the clipboard, so they discourage copying their password into clipboard. But intercepting keystrokes to another program (at least in Windows) doesn't require any special permissions either. Would the concern more be background web tabs (cross-site) accessing the global clipboard? Vaguely recall that was possible a long time ago but likely locked down now.

As the article points out, for malicious sites that was true on IE 6 but no longer, and for malicious local software you have bigger problems.

Re: Let them paste passwords (2017)

#13
post #11

Seems a plausible concern that malware on the PC can access the clipboard, so they discourage copying their password into clipboard. But intercepting keystrokes to another program (at least in Windows) doesn't require any special permissions either. Would the concern more be background web tabs (cross-site) accessing the global clipboard? Vaguely recall that was possible a long time ago but likely locked down now.

If there is malware on the pc then the browser itself must be assumed compromised. It's futile to half plug one small hole while a million others exist.

And by attempting to plug that hole you've added an inconvenience that may encourage users to use a less secure password.

Re: Let them paste passwords (2017)

#14
Making password entry difficult is like attempting weight loss by eating bland food.

It's not the flavour that makes you fat.

Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance. An element of punishing oneself for past transgressions seems essential.

Security people have the same mindset. Security must be a hassle. It must be in your face. It has to be onerous. A challenge. A hurdle to get past.

I've tried, over and over, to explain to my customers that often the slickest, most hassle-free approach is the most secure. But this almost never sells.

Meanwhile, I see vendor after vendor successfully selling products that exist only to irritate users.

Re: Let them paste passwords (2017)

#16
post #6
post #5

Being a Firefox user, I have set dom.event.contextmenu.enabled and dom.event.clipboardevents.enabled set to false, so that I can continue right-clicking and pasting.

Is there a way to quickly toggle those on and off?

I'm not sure if it's the same thing, but usually, holding shift while right clicking enables the context menu in Firefox.

Re: Let them paste passwords (2017)

#17
post #5

Being a Firefox user, I have set dom.event.contextmenu.enabled and dom.event.clipboardevents.enabled set to false, so that I can continue right-clicking and pasting.

I recommend checking out the "Don't F$#k with Paste" extension which allows you to essentially control the setting per site: https://addons.mozilla.org/firefox/addon/don-t-fuck-with-pas...

There is also a version for Chrome: https://chrome.google.com/webstore/detail/dont-fuck-with-pas...

EDIT: Made the link locale independent and censored the name better.

Re: Let them paste passwords (2017)

#18

Making password entry difficult is like attempting weight loss by eating bland food. It's not the flavour that makes you fat. Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance . An element of punishing oneself for past transgressions seems essential . Security people have the same mindset. Security must be a hassl…

Sounds like Calvinism: https://redd.it/232qqq

Re: Let them paste passwords (2017)

#20
post #6
post #5

Being a Firefox user, I have set dom.event.contextmenu.enabled and dom.event.clipboardevents.enabled set to false, so that I can continue right-clicking and pasting.

Is there a way to quickly toggle those on and off?

Why do you need to toggle them? Isn't pasting and right clicking useful everywhere?
Post reply on HN