Large corporate/government IT lives on another plane of existence. Rules are made in some far-flung office and enforced through edicts that can't be challenged, partly because nobody knows exactly who created them, partly because nobody wants to stand out, and partly because yes-men surround the upper levels of management.
Anyway, somebody somewhere about a decade ago seems to have injected into the heads of such rule-makers that users who paste their password confirmations defeat the purpose of the confirmation mechanism, which was leading to excess support requests for forgotten passwords. So, therefore, pasting into the confirmation box (or even better, both boxes) should be disabled.
Never mind that password rules have gotten more complex, that allowing users to temporarily preview their passwords instead is now recommended, or that the use of password managers and online password resets means even if the original concern were valid, it's now moot. The rule exists, and so it must be followed.
At some point these corporations do lurch forward (or die), so eventually this will get changed, but it'll happen way slower than it should.
Anyway, somebody somewhere about a decade ago seems to have injected into the heads of such rule-makers that users who paste their password confirmations defeat the purpose of the confirmation mechanism, which was leading to excess support requests for forgotten passwords. So, therefore, pasting into the confirmation box (or even better, both boxes) should be disabled.
Never mind that password rules have gotten more complex, that allowing users to temporarily preview their passwords instead is now recommended, or that the use of password managers and online password resets means even if the original concern were valid, it's now moot. The rule exists, and so it must be followed.
At some point these corporations do lurch forward (or die), so eventually this will get changed, but it'll happen way slower than it should.