Hopefully most are updating the property and not the attribute.
this.input.value = 'password';
This would be fine. However updating the attribute (the way React recommends it with controlled components) would be something like: <input type="text" value={this.state.value} onChange={this.handleChange} />
This would be vulnerable to the the CSS keylogger.https://reactjs.org/docs/uncontrolled-components.html#defaul...
You can use a form and grab the values on submission.
<form onSubmit={this.handleSubmission}>
<input type="password" name="password" />
</form>
this.handleSubmission = event => {
// access to event.target.password.value
}