Say it with me kids:

Disabling paste on your password entry makes your users' accounts LESS secure.

Stop making your users less secure.
Stop It.

@saramg One step more evil: allow the user to paste the password, but use some trickery to determine that it came from a paste event rather than keystrokes so you can mark it "incorrect" - even if typing it manually would yield the same result.

I'm pretty sure this happens on one of those sites I only need every other year.

