Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Disabling pasting requires disabling JavaScript in a real end-user browser with an end-user who doesn't know how to un-disable pasting.

Never trust the client['s computer]. Disabling pasting is trusting the client's computer. Security in depth ends where the Internet starts.



One could argue that a cross site scripting attack could use someone else's browser to paste to the site. So disabling paste disables one (small) vector for an attacker to use someone else's computer to attack.


This - I just realized the thing I was working on was supposed to be used in a public setting.


Deleted my comment but I just realized why we did this -

The product I was working on was to be used on a shared public browser / kiosk. The reason was to prevent one user from pasting in the previous user's password.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: