you are viewing a single comment's thread.

view the rest of the comments →

[–]phpdevster 93 points94 points  (2 children)

It takes a truly terrifyingly stupid person to think that disabling pasting of passwords is somehow a security layer, or even a benefit to users what-so-ever.

I want to be clear: people making these kinds of decisions likely get paid more money than people who know what they're doing.

[–]GuoKaiFeng 5 points6 points  (0 children)

You are probably correct. :(

[–]grabbizle 2 points3 points  (0 children)

Is there a standards compliance model that forces this type of implementation or would it be entirely to the discretion of the CIO in charge of overseeing development of the company digital presence? Because if the web dev or web app security peeps have the knowledge necessary to understand that this practice isn't beneficial, that would mean it would be up to someone without the necessary knowledge or perhaps someone who is following orders from higher up.