Investigating the impact removing password masking has on consumer trust (2014)
passwordmasking.com
passwordmasking.com
> How often is someone looking over your shoulder when you type a password?
When I'm in the privacy of my own home? Rarely. When I'm using a mobile device (arguably where "unmasking" provides the most usability improvement) in public? All the time. No, random strangers are most likely not paying attention to your phone, but look around next time you go out there are cameras _everywhere_.
Even the helpful mobile keyboard feature that shows you the last entered character is a risk. Not to mention merely watching the interaction with the onscreen keyboard. However, both of those require a moderate amount of attention, versus just prominently displaying the full password unobstructed all at once on the screen.
You may not think those cameras matter, but let's be honest, many people have access to the data feed through those cameras. From the near-minimum-wage "security" guard (or loss prevention) employee to the corporate security teams storing the backed up footage.
Logging into your Hacker News account may present a low risk, but certainly, this could be catastrophic when logging into your bank account. It's one of the less acknowledged benefits of fingerprint readers and password managers (combined). Unmasking that password entered by the password manager would defeat this entirely.
Let it be an option, but don't do this by default.
Fully agree, and found the "As for what you should set the default to. Well that’s another question..." conclusion quite stupid to be honest; "80% were not expecting to see the password as clear text" and "60% said they had become suspicious of the site", on those metrics alone surely it's obvious the default should be masked with an option to reveal.
I’d rather have password masking be the default everywhere.
Consider for example lecturers using the computer in a room full of people, prominently displaying their screen on the projector for all to see. Or anyone in a business meeting for that matter, using a projector or sharing their screen through teleconferencing.
If you are fast at typing you could type out a lot of your password before catching the fact that everyone is seeing your password.
And if you are a hunt-and-peck typist you might be slow but you might also be looking at the keyboard the whole time as you are typing out your password, and therefore not catch the fact that everyone is seeing your password.
In that case, the cameras can also capture which keystrokes are being typed.
See the problem? Whenever you typed a password, you would see all the letters you typed lit up on the keyboard conveniently in brightness order...
clever trick with the infra cam, but i don't think you've showed the equivalence of the situations in any practical sense. maybe that wasn't your point, and you were just offering a sorta-similar-but-not-really detection technique?
Reminds me of the scene in one of Dan Brown's books where they catch the protagonist by noticing a conveyor belt has warmed up (which he lay on to escape). The first time I read that I thought it was nonsense, but having used decent cameras I'm inclined to believe it now.
> You may not think those cameras matter, but let's be honest, many people have access to the data feed through those cameras. From the near-minimum-wage "security" guard (or loss prevention) employee to the corporate security teams storing the backed up footage.
yeah, this is a thought that has crossed my mind a lot the last couple years, and i find it really unnerving. i now consciously try to keep my typing out of the sight line of cameras, though i don't always remember to do that, and i'm sure there are tons of cameras i don't notice.
> In order to assist the claimant in successfully entering a memorized secret, the verifier SHOULD offer an option to display the secret — rather than a series of dots or asterisks — until it is entered. This allows the claimant to verify their entry if they are in a location where their screen is unlikely to be observed.
1) This needs a [2014] tag.
2) This encourages password re-use and the 2019 guidance really needs to focus on generating unique passwords for each site / property and storing it somewhere secure. The push to move to other forms of security has never been stronger.
I don't think showing the password would actually encourage to re-use a password, but hiding the password may encourage to use a password manager and unique passwords.
I use a good password manager with long, unique, random passwords.
The world is messy, though, and some small fraction of the apps/sites/devices/contexts I need to enter credentials stored in my password manager require manual entry. Some of these are on a device with the password manager, but fail to support auto-fill and block paste. Some of these are on other devices (such as TV streaming boxes). It also applies to every login I need to enter on a new device before my password manager is installed and unlocked.
When I have to enter dozens of high-entropy characters on mobile keyboards, TV remotes, or my sad 3rd-gen MacBook butterfly keyboard, a simple unmasking toggle is a lifesaver. Its absence is a misery/frustration multiplier. I'm not sure how the initial login on an iPhone is, but it took me 4 tries to log in on my newest Android because I had to enter ~40 characters while swapping between the stock alpha/symbol keyboards without an unmask.
I'm sold on the value of using a password manager and aware of the risks of not doing it, so these frictions won't deter me. But I'd be surprised if I'm in the majority, here. I suspect many people will fail into partial or complete non-compliance with the password manager if they regularly encounter these scenarios (or encounter them while the costs of abandoning the effort are still minimal).
This should never be the default.
It's the old dilemma of machine-only protocols vs protocols that can be spoken by a human typing on a keyboard.
Say, can you tell me what the recovery process is if your Yubikey croaks while you're on a trip away from home?
Every option has drawbacks.
As for the yubikey croaking, easy: carry a backup.
Summary: removing masking doesn't erode consumer trust if it's optional, but they get leery of you if it's off by default.
On desktop, like other people, I do type passwords while not alone in front of the screen, and masking is fine.
It is just about giving the impression of being secure?