Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. The Lounge
  3. Bad Ideas In Security: Paste Frustration

Bad Ideas In Security: Paste Frustration

Scheduled Pinned Locked Moved The Lounge
androidcomsecuritytoolshelp
37 Posts 11 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R raddevus

    dandy72 wrote:

    Does your password manager not offer an option to simulate keystrokes

    Simulating keystrokes is more difficult in an Android app and it is the Android app that they (bank) removed the paste ability from.

    D Offline
    D Offline
    dandy72
    wrote on last edited by
    #28

    I see. As far as I'm concerned...considering the number of Android devices out there that have known exploits that'll never be patched, because OEMs can't be bothered...all banks should block Android altogether. I rarely side with banks, but Android device vendors are downright irresponsible. IMNSHO.

    R 1 Reply Last reply
    0
    • L Lost User

      You better stock up on lawyers then :)

      Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

      R Offline
      R Offline
      raddevus
      wrote on last edited by
      #29

      Eddy Vluggen wrote:

      You better stock up on lawyers then

      Exactly why I have not written the article. :sigh: However, did you see the update to my post? I found an article from the National Cyber Security Centre which also has links to Troy Hunt's explanation on why pasting is safe and important and it has a link to a Wired article 2015 which has very interesting info on why pasting should(must) be available in apps.

      L 1 Reply Last reply
      0
      • D dandy72

        I see. As far as I'm concerned...considering the number of Android devices out there that have known exploits that'll never be patched, because OEMs can't be bothered...all banks should block Android altogether. I rarely side with banks, but Android device vendors are downright irresponsible. IMNSHO.

        R Offline
        R Offline
        raddevus
        wrote on last edited by
        #30

        Ok, I can accept that Android devices are vulnerable. That's fine. But, then, the resolution for the bank is not to disallow pasting...it is to disallow the use of an Android device altogether. In other words, they shouldn't have ever created an Android app in the first place. I would accept that decision more readily than the blocking paste solution. But then that would mean they needed to block the web site from Android Web browsers too. :-D It would be interesting and funny if the bank just came out and said, "Sorry, you can only use our e-banking via Apple devices."

        D 1 Reply Last reply
        0
        • R raddevus

          Eddy Vluggen wrote:

          You better stock up on lawyers then

          Exactly why I have not written the article. :sigh: However, did you see the update to my post? I found an article from the National Cyber Security Centre which also has links to Troy Hunt's explanation on why pasting is safe and important and it has a link to a Wired article 2015 which has very interesting info on why pasting should(must) be available in apps.

          L Offline
          L Offline
          Lost User
          wrote on last edited by
          #31

          So, if I find the tweet, I'll know the bank by name? :-D

          Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

          R 1 Reply Last reply
          0
          • L Lost User

            So, if I find the tweet, I'll know the bank by name? :-D

            Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

            R Offline
            R Offline
            raddevus
            wrote on last edited by
            #32

            Eddy Vluggen wrote:

            So, if I find the tweet, I'll know the bank by name?

            :laugh: :laugh: I hope you find it. :thumbsup: It was a DM (direct message) tweet though so I don't think you can see it in my twitter. Good luck though! :thumbsup:

            L 1 Reply Last reply
            0
            • D dan sh

              Raj is (or was?) a nice guy. Come to think of it, with Aussies and their compulsive behaviour to shorten up words, you might as well be referred to as Raj.

              "It is easy to decipher extraterrestrial signals after deciphering Javascript and VB6 themselves.", ISanti[^]

              R Offline
              R Offline
              Rajesh R Subramanian
              wrote on last edited by
              #33

              lw@zi wrote:

              Come to think of it, with Aussies and their compulsive behaviour to shorten up words, you might as well be referred to as Raj.

              It's kind of why I said it's likely to be "another Raj". That, and the outsourcing to India. :-)

              1 Reply Last reply
              0
              • R raddevus

                Our large bank recently changed their Android app so you can no longer paste a password. :sigh: This is a MAJOR problem if you're using a password manager. I don't type passwords any more. I contacted them (via their Twitter support) and explained that this is a security fallacy that pasting is dangerous. Also, you can still paste a password when you login on their web site. I wanted to mention that to them but was afraid they'd stop it there too. May Only Prove That The Bank Devs/ Contractors Are Clueless To me this only exposes the fact that the developers or security contractors or whatever actually have NO CLUE about WHAT SAFE PRACTICES are. They could even remove copy functionality separately and I would be ok with that. But how could the paste functionality EVER be an exposure? They are just so clueless. :| EDIT 09/24/2018 Look what I found from the National Cyber Security Centre: Let them paste passwords - NCSC Site[^] And it provides additional links as to why pasting should be allowed. I tweeted this to the bank site. EDIT 2 09/24/2018 Check out this Wired article and the associated quote: https://www.wired.com/2015/07/websites-please-stop-blocking-password-managers-2015/[^]

                Wired:

                But accounts aren't broken into by repetitive copy and pasting. One hacker told WIRED that disabling paste on a webpage does not stop him from using automated tools to speedily gain access to users’ accounts.

                S Offline
                S Offline
                sir_download_alot
                wrote on last edited by
                #34

                Not being able to past my password or using a password manager will force me to use a password that potentially are unsafe because I need to write them down or they are easy to guess.

                R 1 Reply Last reply
                0
                • R raddevus

                  Eddy Vluggen wrote:

                  So, if I find the tweet, I'll know the bank by name?

                  :laugh: :laugh: I hope you find it. :thumbsup: It was a DM (direct message) tweet though so I don't think you can see it in my twitter. Good luck though! :thumbsup:

                  L Offline
                  L Offline
                  Lost User
                  wrote on last edited by
                  #35

                  I don't have/use twitter; I assumed all tweets were public :)

                  Bastard Programmer from Hell :suss: If you can't read my code, try converting it here[^] "If you just follow the bacon Eddy, wherever it leads you, then you won't have to think about politics." -- Some Bell.

                  1 Reply Last reply
                  0
                  • S sir_download_alot

                    Not being able to past my password or using a password manager will force me to use a password that potentially are unsafe because I need to write them down or they are easy to guess.

                    R Offline
                    R Offline
                    raddevus
                    wrote on last edited by
                    #36

                    sir_download_alot wrote:

                    will force me to use a password that potentially are unsafe

                    Exactly! It just makes no sense to remove paste functionality.

                    1 Reply Last reply
                    0
                    • R raddevus

                      Ok, I can accept that Android devices are vulnerable. That's fine. But, then, the resolution for the bank is not to disallow pasting...it is to disallow the use of an Android device altogether. In other words, they shouldn't have ever created an Android app in the first place. I would accept that decision more readily than the blocking paste solution. But then that would mean they needed to block the web site from Android Web browsers too. :-D It would be interesting and funny if the bank just came out and said, "Sorry, you can only use our e-banking via Apple devices."

                      D Offline
                      D Offline
                      dandy72
                      wrote on last edited by
                      #37

                      Yep...sad, isn't it?

                      1 Reply Last reply
                      0
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • World
                      • Users
                      • Groups