Live data from Hacker News

Let them paste passwords (2017)

ncsc.gov.uk

21–30 of 129 posts

Re: Let them paste passwords (2017)

#21

Making password entry difficult is like attempting weight loss by eating bland food. It's not the flavour that makes you fat. Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance . An element of punishing oneself for past transgressions seems essential . Security people have the same mindset. Security must be a hassl…

There was a recent discussion on HN that branches into this idea about the importance of UX. I agree with you, with a twist.

What you want is that the happy path for security is zero hassle, but the unhappy paths should also drop dead with zero hassle.

This is the UX I really like for WebAuthn / U2F.

All the interactions on the happy path are very smooth. Need a second factor, tap, go. Almost frictionless. On my phone for example you tap the same fingerprint sensor that would ordinarily unlock the phone. Short of not having a second factor at all it couldn't be smoother.

But if this is actually a phishing site or you're a crook who doesn't have the hardware token, it just doesn't work. Still low friction in a sense, but low friction failure. There is no way forward, no override, no "I'm sure", nothing - it just won't work.

Re: Let them paste passwords (2017)

#22

Making password entry difficult is like attempting weight loss by eating bland food. It's not the flavour that makes you fat. Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance . An element of punishing oneself for past transgressions seems essential . Security people have the same mindset. Security must be a hassl…

Years ago I believe it was Microsoft that found via some method that the higher the rate of required password changes + difficult password rules...the more likely they found larger / more obvious security issues.

Re: Let them paste passwords (2017)

#24

What password manager do you use? Have been using Avast PW Manager but appears to no longer be maintained.

I’m a happily paying user of 1Password personally, although I’ve used bitwarden in the past and it’s great and self hostable too. I just prefer 1pass for its fast updates and great integration with the Apple ecosystem. If you wanna host your data with gdrive or the like keepass is less polished but also very solid.

Re: Let them paste passwords (2017)

#26
post #3

So much of main line security practice is cargo cultism. There is so little use of actual research and data on how compromises actually happen. Somebody just gets the idea something is good for security and it sticks. No rationale needed.

Related to this, every security team I’ve ever interacted with barely knows how to work a computer and mostly operates off of commercially purchased scanning tools and security agents.

My theory is that security is the least desirable part of the entire software engineering stack - it’s boring, has a lot of blame and liability potential, and it’s a cost center. Heck at least infrastructure folks get to brag about things like cost optimizations.

As a result it seems to me that security attracts the kind of people who view it as a way to wear a digital uniform and badge.

Re: Let them paste passwords (2017)

#27

Making password entry difficult is like attempting weight loss by eating bland food. It's not the flavour that makes you fat. Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance . An element of punishing oneself for past transgressions seems essential . Security people have the same mindset. Security must be a hassl…

There was a recent discussion on HN that branches into this idea about the importance of UX. I agree with you, with a twist. What you want is that the happy path for security is zero hassle, but the unhappy paths should also drop dead with zero hassle. This is the UX I really like for WebAuthn / U2F. All the interactions on the happy path are very smooth. Need a second factor, tap, go. Almost frictionless. On my phon…

Aside: it'd be cool to have a tool that could find the discussion you referenced in your first sentence. I wonder if Algolia is working on something in the space of topical search.

Re: Let them paste passwords (2017)

#28

Making password entry difficult is like attempting weight loss by eating bland food. It's not the flavour that makes you fat. Nonetheless, there's this perception that something delicious can't be good for a diet. People have this notion that to lose weight, there must be penance . An element of punishing oneself for past transgressions seems essential . Security people have the same mindset. Security must be a hassl…

> Security people have the same mindset. Security must be a hassle.

It's an unhelpful generalisation. There are many jobs that could come under "Security people" and they work under different requirements.

Many will agree with you on the hassle-free experience. There's no need for the us-vs-them.

Re: Let them paste passwords (2017)

#29
post #25

Is that first image real? I don't think I've ever seen JavaScript graffiti before...

Highly unlikely, I think. The letters are too crisp. And the way the text follows the corners, while cleverly done, don’t reflect the way real graffiti would be done.

Re: Let them paste passwords (2017)

#30
post #6

Earlier quoted context omitted.

Is there a way to quickly toggle those on and off?

Why do you need to toggle them? Isn't pasting and right clicking useful everywhere?

Some SPAs and other sites have useful right click actions that I want to preserve. Does this setting disable those?

(For the pasting, I agree with you. I can't think of a single reason I'd want a website to prevent me from pasting)

Post reply on HN