The fact that anyone would prevent users from "pasting" their password is outrageous. To have a long randomized password is the most basic web-security practice, and a password manager is essential for most users trying to implement the practice.
I believe that publishers deliberately prevent paste into the password field are either: malicious, or they themselves lack adequate security, most certainly they lack the basic implementation of security practices, which is AA?
DerekClair about American Airlines, v4.8.0