Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. If you disable pasting in your password field, I hate you.

If you disable pasting in your password field, I hate you.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
22 Indlæg 18 Posters 72 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • brainblasted@crab.gardenB brainblasted@crab.garden

    If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

    magnetic_tape@infosec.exchangeM This user is from outside of this forum
    magnetic_tape@infosec.exchangeM This user is from outside of this forum
    magnetic_tape@infosec.exchange
    wrote sidst redigeret af
    #12

    @brainblasted
    The underlaying issue here is that modern OSes generate a paste event instead of simulating a typing keycodes event which would prevent any shennigans like this to work in the first place

    1 Reply Last reply
    0
    • brainblasted@crab.gardenB brainblasted@crab.garden

      If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

      kdude@mastodon.socialK This user is from outside of this forum
      kdude@mastodon.socialK This user is from outside of this forum
      kdude@mastodon.social
      wrote sidst redigeret af
      #13

      @brainblasted so annoying... on desktops i have a system-wide keyboard shortcut which triggers "type the clipboard contents", as a workaround.

      cppguy@infosec.spaceC 1 Reply Last reply
      0
      • kdude@mastodon.socialK kdude@mastodon.social

        @brainblasted so annoying... on desktops i have a system-wide keyboard shortcut which triggers "type the clipboard contents", as a workaround.

        cppguy@infosec.spaceC This user is from outside of this forum
        cppguy@infosec.spaceC This user is from outside of this forum
        cppguy@infosec.space
        wrote sidst redigeret af
        #14

        @Kdude

        Interesting! Which OS are you using, and how did you set up the shortcut?

        @brainblasted

        kdude@mastodon.socialK 1 Reply Last reply
        0
        • brainblasted@crab.gardenB brainblasted@crab.garden

          If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

          fenixmaster@mastodon.socialF This user is from outside of this forum
          fenixmaster@mastodon.socialF This user is from outside of this forum
          fenixmaster@mastodon.social
          wrote sidst redigeret af
          #15

          @brainblasted I use a simple paper boolet with A, B, C, .... and pretty complex passwords with subtitution parts, some more than 20 character long. The substitution parts are not known in the booklet, only in my mind. I never trust password managers.

          1 Reply Last reply
          0
          • brainblasted@crab.gardenB brainblasted@crab.garden

            If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

            pascaline@mastodon.nlP This user is from outside of this forum
            pascaline@mastodon.nlP This user is from outside of this forum
            pascaline@mastodon.nl
            wrote sidst redigeret af
            #16

            @brainblasted

            Oh yes, that's so bad.
            I have an app here on the phone that does not allow pasting. I've been silently ranting and raging about it. Internalisation is a thing.

            1 Reply Last reply
            0
            • cppguy@infosec.spaceC cppguy@infosec.space

              @Kdude

              Interesting! Which OS are you using, and how did you set up the shortcut?

              @brainblasted

              kdude@mastodon.socialK This user is from outside of this forum
              kdude@mastodon.socialK This user is from outside of this forum
              kdude@mastodon.social
              wrote sidst redigeret af
              #17

              @CppGuy @brainblasted Linux: Espanso
              Previously, macOS: Keyboard Maestro

              https://espanso.org/docs/

              1 Reply Last reply
              0
              • brainblasted@crab.gardenB brainblasted@crab.garden

                If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

                the5thcolumnist@mstdn.caT This user is from outside of this forum
                the5thcolumnist@mstdn.caT This user is from outside of this forum
                the5thcolumnist@mstdn.ca
                wrote sidst redigeret af
                #18

                @brainblasted

                Password show buttons should be de-rigour and obvious. Everyone is not entering passwords with someone looking over their shoulder, I would suggest most people are not,

                1 Reply Last reply
                0
                • brainblasted@crab.gardenB brainblasted@crab.garden

                  If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

                  cbrocas@infosec.exchangeC This user is from outside of this forum
                  cbrocas@infosec.exchangeC This user is from outside of this forum
                  cbrocas@infosec.exchange
                  wrote sidst redigeret af
                  #19

                  @brainblasted I lived that particular moment so many times 💯

                  1 Reply Last reply
                  0
                  • brainblasted@crab.gardenB brainblasted@crab.garden

                    If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

                    haayman@todon.nlH This user is from outside of this forum
                    haayman@todon.nlH This user is from outside of this forum
                    haayman@todon.nl
                    wrote sidst redigeret af
                    #20

                    @brainblasted Do you know what a bookmarklet is? It's a tiny javascript that you can add to your bookmarks at the top of the page. Instead of having an URL in the target, you add this script.
                    If you click on the link, it will find all password fields on the page and turn it into a regular input field to make the content visible. It is harmless and has no impact on the workings of the page

                    ```
                    javascript:(function(){
                    document.querySelectorAll('input[type="password"]').forEach(el => el.type = 'text');})()
                    ```

                    brainblasted@crab.gardenB 1 Reply Last reply
                    0
                    • haayman@todon.nlH haayman@todon.nl

                      @brainblasted Do you know what a bookmarklet is? It's a tiny javascript that you can add to your bookmarks at the top of the page. Instead of having an URL in the target, you add this script.
                      If you click on the link, it will find all password fields on the page and turn it into a regular input field to make the content visible. It is harmless and has no impact on the workings of the page

                      ```
                      javascript:(function(){
                      document.querySelectorAll('input[type="password"]').forEach(el => el.type = 'text');})()
                      ```

                      brainblasted@crab.gardenB This user is from outside of this forum
                      brainblasted@crab.gardenB This user is from outside of this forum
                      brainblasted@crab.garden
                      wrote sidst redigeret af
                      #21

                      @haayman til! Thanks for the tip

                      1 Reply Last reply
                      0
                      • brainblasted@crab.gardenB brainblasted@crab.garden

                        If you disable pasting in your password field, I hate you. I hate you even more if you don't have a "show password" button so I can verify that I'm typing my password correctly since you won't let me paste

                        cwant@mathstodon.xyzC This user is from outside of this forum
                        cwant@mathstodon.xyzC This user is from outside of this forum
                        cwant@mathstodon.xyz
                        wrote sidst redigeret af
                        #22

                        @brainblasted this is all true, but my least favorite is "I'm only gonna give you three tries then lock you out". (Nobody can brute force a password in three tries, so what problem is that solving?)

                        1 Reply Last reply
                        0
                        • anderslund@expressional.socialA anderslund@expressional.social shared this topic
                        Svar
                        • Svar som emne
                        Login for at svare
                        • Ældste til nyeste
                        • Nyeste til ældste
                        • Most Votes


                        • Log ind

                        • Har du ikke en konto? Tilmeld

                        • Login or register to search.
                        Powered by NodeBB Contributors
                        Graciously hosted by data.coop
                        • First post
                          Last post
                        0
                        • Hjem
                        • Seneste
                        • Etiketter
                        • Populære
                        • Verden
                        • Bruger
                        • Grupper