Is blocking use of password managers really increased security?

  • DNS Benchmark v2 Release 5 with Consultant License
    Guest:
    If you own any earlier release of our DNS Benchmark you may immediately download its release #5 replacement. Running an earlier release will detect the new release and help you upgrade.

    Although this release is cosmetic, appearance matters and affects ease of use. The biggest change, as seen in the image above, is that the DNS Benchmark now has a traditional Windows application menu to more fully expose its many features. This release is also "Consultant License Aware" and GRC will now issue a Consultant version when owners have previously purchased four "Personal Use" licenses. If you have previously purchased four DNSB licenses, or if you wish to upgrade your "Personal Use" license to Consultant, GRC's purchase process will direct you through that process.
    /Steve.
  • Be sure to checkout “Tips & Tricks”
    Dear Guest Visitor → Once you register and log-in please checkout the “Tips & Tricks” page for some very handy tips!

    /Steve.
  • BootAble – FreeDOS boot testing freeware

    To obtain direct, low-level access to a system's mass storage drives, SpinRite runs under a GRC-customized version of FreeDOS which has been modified to add compatibility with all file systems. In order to run SpinRite it must first be possible to boot FreeDOS.

    GRC's “BootAble” freeware allows anyone to easily create BIOS-bootable media in order to workout and confirm the details of getting a machine to boot FreeDOS through a BIOS. Once the means of doing that has been determined, the media created by SpinRite can be booted and run in the same way.

    The participants here, who have taken the time to share their knowledge and experience, their successes and some frustrations with booting their computers into FreeDOS, have created a valuable knowledgebase which will benefit everyone who follows.

    You may click on the image to the right to obtain your own copy of BootAble. Then use the knowledge and experience documented here to boot your computer(s) into FreeDOS. And please do not hesitate to ask questions – nowhere else can better answers be found.

    (You may permanently close this reminder with the 'X' in the upper right.)

Maplegate

New member
Apr 18, 2026
2
0
Chase bank has recently changed their android banking app to prevent pasting username/password during the login dialog. This effectively prevents password managers and complex passwords. Their tech support says their approach is meant to increase security. I argue that it encourages simple, easy-to-type passwords. They offer the option to use a passkey, but I have 2 Chase accounts, and a passkey only supports one set of login credentials. What am I missing here?
 
I have found that after typing the username, 1Password *is* allowed to paste the password. I have opted to make the username easier for me to type, and am now satisfied (but still perplexed).
 
Same issue with a Medical App I have to use Healow. If you don't turn on biometrics, you have to enter a pin every 30 seconds (even mid-typing into the app) and every time you switch away from the app. Biometrics reconfirms every time the app is switched away and every minute or 2.

They don't support direct password manager, but through the context menus, it can be done with 5 taps per field using BitWarden that is IF biometrics is enabled. If PIN is enabled, the switch away to get the username or password causes a PIN entry event, which clears the clipboard. If PIN entry is enabled, you can use the context menus (and 5 taps) for 1 field, because the data in the other field is cleared for some strange reason.

Once you get past that silliness, then you don't need the password again. It is "auto-connected" in the app.

I have easy to type passwords for the doctors that require that app, and that bugs me. There is no way to change the password at some offices once it is set. Good thing there is no financial ties through their service. No saved credit cards, etc.

Discussions with support ended up being told this is the intended design. I have documented the issues, and how they could resolve them, but they are not interested in making it better. I told them I'll use the website, and delete the app.

Banking apps are not this paranoid (Pin every 30 seconds, biometric every 1-2 minutes) and they integrate with password managers just fine.
 
  • Wow
Reactions: Badrod