Read peoples creds and store somewhere, then issue a 'wrong password' msg and exit, resulting in the real login message.
People will just assume they made a typo and continue as if nothing happened.
I've argued before for a genuine out-of-band independent display on machines which can only be written to by some very high privilege process.