Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Don't disable the clipboard on sensitive data #2

Closed
rugk opened this issue Feb 15, 2018 · 1 comment
Closed

Don't disable the clipboard on sensitive data #2

rugk opened this issue Feb 15, 2018 · 1 comment

Comments

@rugk
Copy link

rugk commented Feb 15, 2018

The clipboard is deactivated on text fields that may contain sensitive data.

No, please don't. That prevents many password managers from working (not all of them support Android 8's new APIs). So if the result is users use 12345 as a password (with the result that everyone can login) instead of a good password copied and saved from their password manager (with the potential that other apps may access it), then you've done more harm than good.

@muellerberndt
Copy link
Owner

Hi @rugk, definitely a valid point. This list reflects the OWASP MASVS, so I suggest you take the discussion on the MASVS repo!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants