this post was submitted on 07 Jan 2025
941 points (99.6% liked)

memes

14090 readers
2754 users here now

Community rules

1. Be civilNo trolling, bigotry or other insulting / annoying behaviour

2. No politicsThis is non-politics community. For political memes please go to [email protected]

3. No recent repostsCheck for reposts when posting a meme, you can only repost after 1 month

4. No botsNo bots without the express approval of the mods or the admins

5. No Spam/AdsNo advertisements or spam. This is an instance rule and the only way to live.

A collection of some classic Lemmy memes for your enjoyment

Sister communities

founded 2 years ago
MODERATORS
 
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 129 points 3 months ago (3 children)

Just as evil are the pages that don’t let you select text or pictures for copying.

[–] [email protected] 87 points 3 months ago (2 children)

You can't copy our JPEGs! That's stealing! If you want to look at these JPEGs whenever you want, you need to register for an account and tag your favorites so we can monitor your viewing habits and sell your personality profile to advertisers and government entities!

[–] [email protected] 62 points 3 months ago (1 children)

Meanwhile:

Sure thing, pal! I'm just gonna take a peek at the HTML real quick...

[–] [email protected] 32 points 3 months ago (1 children)

Or for the lazy, screenshot!

[–] [email protected] 4 points 3 months ago

I believe you can hold ALT then select on Firefox when that comes up, but I don't think I've seen it in years.

[–] [email protected] 17 points 3 months ago (1 children)

Or training videos that pause if the window playing the video is not the last thing clicked on.

load more comments (1 replies)
load more comments (1 replies)
[–] [email protected] 55 points 3 months ago (2 children)

I ran into this when trying to paste my generated password into the password field on some kind of financial site and I think it is still the most egregious case of security theater I’ve seen yet.

Anyway, you want the “don’t fuck with paste” extension, available on both chrome and firefox.

[–] [email protected] 44 points 3 months ago* (last edited 3 months ago) (4 children)

You don't need this - In about:config, set dom.event.clipboardevents.enabled to false. No Addon needed.

[–] [email protected] 5 points 3 months ago

The comment hero!

load more comments (3 replies)
load more comments (1 replies)
[–] [email protected] 30 points 3 months ago (2 children)

Especially for things like account numbers. No, you're not increasing security, you idiots, you're increasing human error!

load more comments (2 replies)
[–] [email protected] 28 points 3 months ago (2 children)

It isn't right you need an extension for it, but here we are. Don't F*** With Paste

[–] [email protected] 14 points 3 months ago (1 children)

On Firefox it is some setting under about:config, no need for an extension.

[–] [email protected] 10 points 3 months ago (1 children)

dom.event.clipboardevents.enabled

load more comments (1 replies)
[–] [email protected] 3 points 3 months ago (1 children)

using chrome in the first place

[–] [email protected] 3 points 3 months ago

using characters that need to be escaped in your plugins name

[–] [email protected] 25 points 3 months ago (3 children)

TBF, I kind of get it. If someone is using a public computer you wouldn't want someone to be able to sign into a site they left open because they copied their password.

However, this won't prevent anyone from copying the password into something like notepad and just typing it out. So in the end, it's useless and makes things less user friendly. Which is what I expect these days.

[–] [email protected] 21 points 3 months ago

I suspect the reasoning for it was more along the lines of "if you're pasting the password, that means you probably saved it in a text file on your desktop or something, and you shouldn't do that so let's stop you from doing it". In reality, it probably didn't work to make anyone store passwords more securely, and only made life unnecessarily harder for people with password managers

[–] [email protected] 7 points 3 months ago* (last edited 3 months ago) (2 children)
  1. User pastes something into site
  2. data still pasted as normal
  3. JScript event clears clipboard and tells user that their clipboard was safely cleared.

Literally just as secure and better behavior. Just use your brain for a few seconds.

Edit: Actually it's MORE secure because disallowing paste leaves the password or whatever in the clipboard without the user necessarily realizing it...

load more comments (2 replies)
[–] [email protected] 5 points 3 months ago (1 children)

Public computers should just have their pastebin locked.

They shouldn't mess with things on my personal computer.

[–] [email protected] 11 points 3 months ago

No they shouldn't. They should require a guest account that clears the session on logout. If you fail to log out when you're finished, well, mistakes have consequences. I'm tired of being handcuffed so incompetent people can have their hands held.

[–] [email protected] 17 points 3 months ago (8 children)

Came here hoping someone would explain how to use dev tools to remove that block or if there an addon for that, really hate this kind of restriction

[–] [email protected] 10 points 3 months ago

Firefox often let's you bypass this shit with holding shift + right click or select the text you want to paste and drag and drop it into the field.

[–] [email protected] 7 points 3 months ago

In about:config, set dom.event.clipboardevents.enabled to false.

load more comments (4 replies)
[–] [email protected] 17 points 3 months ago (2 children)

My bank uses a TOTP and they not only block paste, they also block all typing. Instead they popup a modal with a 0-9 digit keypand and the location of each number changes every time.

Effing obnoxious.

[–] [email protected] 6 points 3 months ago* (last edited 3 months ago) (2 children)

That's a security standard preventing keyloggers from guessing your credentials.

[–] [email protected] 11 points 3 months ago

That's ~~a~~ security ~~standard~~ theater pretending to prevent~~ing~~ keyloggers from guessing your credentials.

FTFY

[–] [email protected] 5 points 3 months ago

The TOTP changes every time. For modern totp hashing I'm not sure how many sequential codes a keylogger would need but I'm guessing more than I will ever enter.

Edit, asked ai for an answer to that because I was curious (maybe it's right):

Start AI

That being said, if an attacker were able to collect a large number of TOTP codes, they might be able to launch a brute-force attack to try to guess the private key. However, this would require an enormous amount of computational power and time.

To give you an idea of the scale, let's consider the following:

Assume an attacker collects 1000 TOTP codes, each 6 digits long (a common length for TOTP codes).
Assume the private key is 128 bits long (a common length for cryptographic keys).
Assume the attacker uses a powerful computer that can perform 1 billion computations per second.

Using a brute-force attack, the attacker would need to try approximately 2^128 (3.4 x 10^38) possible private keys to guess the correct one. Even with a powerful computer, this would take an enormous amount of time - on the order of billions of years.

[–] [email protected] 5 points 3 months ago (1 children)

Bank developer played too much RuneScape?

[–] [email protected] 5 points 3 months ago

Lmao I was just about to comment, their bank must have hired a UX designer from Jagex lol

[–] [email protected] 15 points 3 months ago (1 children)

You can sometimes do it anyway by right clicking (or long hold tap) on the text field to get a contextual menu popup

[–] [email protected] 19 points 3 months ago (2 children)

They've started blocking that too on phones, which is what led to this meme lol. Curiously, GBoard has a little button on the top row that shows for freshly copied text when you go into a text field that still works, GBoard must not send the text as a paste when it's done that way. But its only visible once

load more comments (2 replies)
[–] [email protected] 14 points 3 months ago (4 children)

My impression from when I've encountered this is that it is an attempt to repel bots.

Speculating/knowing about the reason doesn't help when I'm confronted with having to input the password *6mA*P7CCuVyHo8kh%x34!63wm23&uhzSMY3Xy3$*8^%7j$VeH^7

[–] [email protected] 13 points 3 months ago

My impression from when I’ve encountered this is that it is an attempt to repel bots.

hmm bots don't use keyboard or mouse copy & paste so I don't see how that makes sense?

my impression is this is just stupid product managers who don't understand why it's a bad idea to force all your users to manually type out their passwords or email addresses just because of the 0.1% of people who would copy and paste one with an error in.

[–] [email protected] 12 points 3 months ago

Bots don't paste. If it a selenium related bot it would inject the value or type out each keypress.

It only causes real users pain

[–] [email protected] 5 points 3 months ago* (last edited 3 months ago)

Weird, that's one character off from my Paramount+ password. I know from typing it on every fucking STB and console that I own and painstakingly quadruple-checking each character when it fails.

You'd think I'd just change to a passphrase but nah. Ain't nobody got time for that. Too busy ranting about user unfriendly problems that shouldn't exist in modern STB apps.

load more comments (1 replies)
[–] [email protected] 12 points 3 months ago (2 children)

I use "don't fuck with paste", a browser extension.

[–] [email protected] 5 points 3 months ago

Nice one, so do I now!

load more comments (1 replies)
[–] [email protected] 11 points 3 months ago (1 children)

Let's be real, though, it's not the dev we should be mad at but some suit who thinks they know security demanding it be done that way

load more comments (1 replies)
[–] [email protected] 7 points 3 months ago (1 children)

no, thats another layer down. hell + ultra

[–] [email protected] 4 points 3 months ago

Lol yea the comic artist needs to come up with a follow-up 4panel with extra-extra-hell lmao

[–] [email protected] 4 points 3 months ago (14 children)

On a similar note, by mobile lemmy client won't let me copy test. Can't even select it.

[–] [email protected] 4 points 3 months ago (2 children)

If you are using Voyager you can hold down on the comment or hit the three dot button and you'll get a menu that gives you a "select text" option. I was annoyed by that until I found it.

load more comments (2 replies)
load more comments (13 replies)
[–] [email protected] 3 points 3 months ago (1 children)
[–] [email protected] 4 points 3 months ago (1 children)

Well, stop. The problem is caused by mid-level managers who think they know better than the Worldwide Web Consortium.

[–] [email protected] 4 points 3 months ago (1 children)

No. The problem is browsers enforcing it.

load more comments (1 replies)
load more comments
view more: next ›