11-04-2016 11:50 PM - edited 01-04-2022 06:03 PM
Sorry if this has been mentioned before, did a search and didn't find anything.
Why doesn't PM allow us to paste passwords for Self-Serve? We can paste passwords for Community. I use a password manager and not allowing us to paste defeats the purpose of a password manager.
I much prefer to use a longer password, but I'm not going to type in a 25+ charact password. Just too prone to error. I've read about this before and I have yet to see anything to convince that disabling paste for password is safer...
11-05-2016 09:32 AM
@pop78 Sorry I think I just misinterpreted the question. I would bet that the real answer is that the functionality was prebuilt into whatever system they are using for my account, I doubt they wrote something from scratch.
Two factor would be nice in the future, but for now with Public as a low cost operator we are probably stuck with what we have.
Althought I went to try it out myself and I can paste into the My Account password field. I'm using Safari on Mac, maybe it was a prebuilt workarround?
11-05-2016 12:21 AM
I'm sure plenty of people can (and probably will) chime in with ways around this. And hey, bring it on! It just goes to prove what a silly "security" measure it is. And now that I've asked the question, any who didn't know of a work around do now.
Just to be clear. I'm not asking for ways around this. I'm asking why it's implemented in the first place. Not actually expecting an official response, but you never know. Maybe they'll remove it and implement something that does add security, like 2 step verification.
11-05-2016 12:06 AM
I use LastPass and chrome and it auto fills the password.
11-05-2016 12:03 AM
Yes, I was aware of these simple work arounds. Just goes to drive home my point that I've yet to see something to convince me that disabling paste for password is safer.
If PM's concern is security, than enable 2 step verification. Disabling paste for passwords is just an inconveniance that forces users to chose simpler/shorter passwords. The reverse of more secure...
11-04-2016 11:54 PM - edited 11-04-2016 11:56 PM
Its for security I belive. There is much more personal information in Self Serve than in Community. I think the theory is that they want you to keep your passwords off your clipboard which is a much more vulnerable part of your computer.
This article touches on getting arround it:
http://www.ghacks.net/2014/07/26/paste-passwords-blocked-form-fields-internet/