Live data from Hacker News

Let them paste passwords

ncsc.gov.uk

21–30 of 376 posts

Re: Let them paste passwords

#21

Assuming you are creating an account, UN: Hello PW: World123 My largest issue is that its extremely possible to fat-finger your UN to be Hellow, and its extremely easy to see and fix that mistake. However since passwords are hidden its hard to see ######## is actually Worls123. Now your new account has essentially a one-time login because you have no idea what your password is. Typing it out again, ensures you catch…

I hate hidden passwords, it's stupid.

I'd notice someone shoulder surfing so I'd prefer if they wheren't starred out by default with starring out as an option if I do have people around.

Re: Let them paste passwords

#22
post #8

"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak

Not really. A sentence for a password is easy to remember and isn't weak.

Re: Let them paste passwords

#23
post #8

"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak

"Probably" being key here. I still memorize all my passwords and the average one is about 30 characters long, with my "more secure" websites going 60+.

Re: Let them paste passwords

#24
post #15

Earlier quoted context omitted.

So by definition your password manager master key is weak? That's an interesting paradox!

It's remembering one password vs X, and it is pretty hard to remember in my case, almost 4 months into using this password and I still struggle to type it in correctly sometimes

Yeah I was just kidding, I see what the parent meant.

Now I use a hardware token (yubikey) to store my PGP key so I can use a relatively weak PIN code on it (since you need to have physical access to the device to use it and you only have 3 attempts before it locks up). It's a pretty good quality of life improvement.

Re: Let them paste passwords

#25

Please correct me if I'm wrong, as this is all conjecture. I feel passwords used to be thought of as a combination of characters that you keep in your head, and should only leave your head when being entered in a password field. Preventing paste discourages storing your password in a file called passwords.txt, and accidentally pasting it somewhere else as well. Of course, we now understand passwords should have some…

Could be, but it's flawed reasoning anyway. Preventing copy/paste won't prevent people from storing their passwords in passwords.txt.

Nobody other than those who use very simple, high risk passwords can remember them all. It has to be stored somewhere. Preventing copy/paste seems like a completely useless step (security wise) that only causes unnecessary bother.

Re: Let them paste passwords

#26
Just yesterday, I ran into a site that was doing this for the first time in years. It annoyed me to the point where I used the console to override it and allow pasting again.

Password managers are a thing. Please don't force me to type out 32 random symbols twice while I sign up for your service.

Re: Let them paste passwords

#27
post #8

"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak

"Probably" being key here. I still memorize all my passwords and the average one is about 30 characters long, with my "more secure" websites going 60+.

Oh, come on. All of them? If you're like me, that’s hundreds. Are you a memorization savant? Are you creating low-quality passwords? Mine are actually long and random (generated NOT by me and NOT four Dr Seuss words)

Re: Let them paste passwords

#28
post #19

I also hate websites that force users use virtual keyboard to enter password.

This is supposed to prevent keylogging.. but I think anything with that amount of access to your PC can tap into the browser to read the request before it's sent. So, probably not as good as it sounds.

Re: Let them paste passwords

#29
post #8

"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its probably too weak

>if you can remember your password, its probably too weak

As XKCD famously pointed out[0], Diceware[1]-style pass phrases can be both secure and memorable. XKCD's four word example isn't secure when fast brute-force attacks are feasible, but eight words is still easily memorable and secure enough for anything. The important point here is that "random words" really does mean "random", i.e. not picked by a human.

[0] https://xkcd.com/936/

[1] https://en.wikipedia.org/wiki/Diceware

Re: Let them paste passwords

#30
post #12

Earlier quoted context omitted.

I can't make any sense whatsoever of it. Does ANY scenario exist where this stops unintended access?

I think it's a combination the "Justification 3" in the article (having passwords stick around in the clipboard could be an issue) and maybe the idea by some people that passwords should be memorized and never written down anywhere. Maybe they're worried people will have a "password.txt" in My Documents where they store all their passwords in cleartext. That being said it'd still probably would be more secure than ha…

It’s not like SPP prevents passwords.txt anyway!
Post reply on HN