Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For one, the clipboard snooping problem. If you’re using a password-manager (like we’re supposed to!) and use it to copy passwords (say, your Amazon employee internal credentials...) while you have TikTok open, the TikTok app would see it and could upload it somewhere.

Your password should never be in your clipboard at least with iOS. If you’re using either the native password manager or a third party password manager, the password manager is directly integrated with the keyboard and would auto fill into your app.

https://techcrunch.com/2018/06/05/password-autofill-in-ios-1...



I use the native password manager–iCloud Keychain. Sometimes I need to copy passwords out of Settings for the handful of circumstances that it doesn't work.


Android does this too. On neither platform does it work 100% of the time, especially in browsers. That's why almost all clipboard managers also have a "copy to clipboard" feature from the autofill view.


It rarely fails for me in the browser, but it fails on me regularly for apps.

The ones that particularly annoy me are the ones that haven't updated to the new Android biometric API versus just supporting the old fingerprint API. I'm looking at you Chase mobile app.


Amazon consistently fails in the browser for me with 1Password + Android.


I’ve never had it not work in the browser.


It's usually a result of the webpage doing stupid stuff to try to explicitly block password managers. There's a lot of banking and government websites that believe this makes things more secure somehow.


Several years ago I tried to register for a website that refused to accept a change of more than one character at a time, using onkeyup and other events to ensure you couldn't fill it in any way other than one letter at a time (fortunately this was only on the asking setup page; it works fine with logging in). After every change in value, it compared the current length to the previous length, and rejected it if the difference was more than one.


It works maybe 90% of the time for me. It seems like a lot of websites don't configure their forms correctly and neither apple password manager nor 1pass detect the field as a password field.


Handoff and 1password, for example. Copy a password on your Mac, and now it's on your phone's clipboard.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: