Live data from Hacker News

Stop Password Masking

useit.com

21–30 of 83 posts

Re: Stop Password Masking

#21
post #14
post #3

Usually this guy's observations are spot on, but this is just wrong. For instance, every time I give a presentation I usually have to login to a secure site. I'm almost always plugged into an overhead projector while I'm logging in. So, not only is this guy suggesting websites change their technology, he's also suggesting users modify their behavior to be more secure. Not going to happen.

> For instance, every time I give a presentation I usually have to login to a secure site. To be fair, he did suggest that password masking was toggled by a checkbox that was ON by default.

It's just too easy to screw that up and despite the argument proferred there is no real benefit. If typing on mobile devices is hard it doesn't seem what we need to do is post our credit card numbers online.

Re: Stop Password Masking

#22
My God, do you even know who "this guy" is? Stop and give it a thought a bit.

He is right about the point, straight on. I've been thinking about implementing it on our web app at aleveo.com like that. Let me elaborate.

We all know that having a simple and usable register/login form increases signups. Let that aside, I've kicking out everything of our forms until really only the necessary. Among those things is the repeat password/email field, username (enough with those) etc. However, what if caps is on, or the keyboard layout is other and so on, the person will signup for your service, but next time he wants to login, if he is having issues with the form, you're done. He'll blame you, as he think he knows what he types as a password.

It is essentially wrong not to see what you are typing. If you noticed, Mr.Nielsen didn't go into implementation. He said that the concept is legacy. A good implementation would be having a checkbox next to the password field "[] show text" or similar, default unchecked.

An older person would definitively appreciate that, but it is not only for them, as it happens to me too (24 year old) to mistake until I figure out what I am really typing in (first keystroke swallowed, typing mistake, caps, wrong layout, etc)

Re: Stop Password Masking

#23
post #9

I think it would be good if browsers came with an option to mask or don't mask passwords. But I don't know if it would work, since the users who would find and change that option would be the heavy users, that have almost no trouble with passwords. If only that option could be easily showed and asked for simple users: a little icon within password boxes showing if it's masked or not, and a hotkey / click on the icon…

Even if you could make it easy to find such an option, you'd just be giving the users the loaded gun to shoot themselves with.

Well that's actually their responsibility...

However they would appreciate the feature if they can't manage to make their password work (e.g. caps lock, different keyboard layout, etc.)

Re: Stop Password Masking

#24
post #10

At least when setting or changing passwords, I would like an option to display them in clear text. Slightly on-topic: I find it silly for a shopping website to display your complete credit card information in plain letters on screen, while masking your login password. The credit card info can be misused to empty your bank account, while the login password can be misused to ... what? Send obscene support requests and…

> Send obscene support requests and muck about with your digital shopping cart?

That, and if your credit card is stored on their servers, which your statement implies, it'd be easy for me to buy stuff on behalf of you. Right now, I'm buying you a new 72 inch Plasma screen which you can't afford. Have fun returning it!

Of course, I could send that plasma to myself, but it'd be stupid of me to do so, since I'd be giving away my where abouts.

Re: Stop Password Masking

#25
He is sure right about the reset button though. I can't be the only one who has entered a dozen or more fields only to lose it all with an inadvertent reset rather than submit.

Also, how about the iPhone compromise? It displays the last character you typed for only an instant.

Re: Stop Password Masking

#26

Unfortunately usability doesn't necessarily coincide with security. If you have to choose between the two, security always wins.

I have to disagree. Who wins between usability and security depends on the application you're using/building.

Rarely there is one good solution to fit all problems.

Re: Stop Password Masking

#27

Disagree. Even bullets shouldn't be displayed while the user types the password. Why should a security camera in an office know that the user's password length is ten, twelve or twenty nine characters?

If you have a well chosen password and it is that long, knowing how long your password is won't be enough for the office snoop to crack the password. I'd be more worried about the camera watching which keys I'm pressing.

On the other hand, if I start typing my password too soon after the login box appears on my laptop, it eats the first character. I would never have worked out why I was finding it so hard to login if the password box did not display bullets. (See also dodgy keyboards.)

Re: Stop Password Masking

#29
post #2

This guy must have been joking. The fact that HE always types his passwords alone in his office does not mean that any sane person would like a possibility that anyone ever has a chance to see his password. Apparently, some people are not always alone...

Yes, good luck to anyone in (a) an open-plan office or (b) an office with security cameras.

Are the security cameras trained on the screen or the keyboard?

Re: Stop Password Masking

#30
post #2

This guy must have been joking. The fact that HE always types his passwords alone in his office does not mean that any sane person would like a possibility that anyone ever has a chance to see his password. Apparently, some people are not always alone...

> The fact that HE always ...

I agree with this statement entirely, but wonder if in a mobile setting, like with an iPhone if this isn't a bad idea. There have been many times where I tried to look over at someones iPhone to see what they were doing and simply couldn't see. I'm talking as close as 2 feet away.

And since I know how annoying it can be to type passwords on my iPod Touch, I could see the value of this--but only on devices with very small screens, and WITHOUT any sort of auto-fill from the browser. Of course, it should be an opt-in sort of setting. No vendor should decide your fate when it comes to security decisions like this.

Post reply on HN