Repeat after me: Blocking paste on a form textbox is not a security feature.
30 comments
@nzakas and, incidentally, will likely then fail proposed WCAG 2.2 SC 3.3.8 Accessible Authentication https://www.w3.org/TR/WCAG22/#accessible-authentication-minimum @isaaccp @nzakas Oh yeah, forgot I hate it when people fail to name-and-shame. It's #Smartsheet. And then once I finally got in, it turns out when a paid user invites you to comment, you can't comment with a free account, but it doesn't tell you that until you find an obscure FAQ. Screw you, Smartsheet. There is one password field with which I work which fills in the entire space with asterisks, no matter how many characters have been typed. This is not, as you might suspect, particularly conducive to first-try entry. @nzakas @lisamelton It has been my career experience that such systems are almost always mandated by people who don't have to use them daily, if at all. It is such a pervasive anti-pattern used by folks who (mistakenly or not) confuse "security theatre" for security. My bank is still not listening 🦻 They want their customers to use longish passwords and they also block the paste functionality 🔑 One can always drag-drop the text into the paste protected field without any problem. No need for extensions. @hakerdefo @nzakas Why is the browser letting the site distinguish between paste and dragged text? 🤔 🤬 @nzakas @lisamelton AMEN! (I'm not religious but that's how strongly I agree with your statement. 😀) @nzakas Especially when you use a password manager. As if I'm going to type my 32 character random number/letter/symbol password by hand - I just open the console and stuff it in with JavaScript lol @nzakas @colarusso_algo Just went into the inspector and removed the paste event override from three input boxes on my insurance company’s site so I didn’t have to type my account information by hand and probably mess it up. The one I have in my clipboard is accurate, I promise. @nzakas I hacked together an Alfred workflow a couple months back after getting particularly pissed at a site that did this. The workflow turns the clipboard into simulated keystrokes and uses AppleScript to type them. I get a little glee every time I use it on a site. @nzakas this is adjacent to Dumb Password Rules @dumbpasswordrules @nzakas Flip side: creating an API that allows sites to block paste or otherwise distinguish between paste and manual entry of characters is malice by the browser. |
@nzakas Stop the madness is your friend!
https://underpassapp.com/StopTheMadness/