Why Masked Passwords Are a Serious Security Hole
blog.passpack.com
blog.passpack.com
We run into it quite a bit, because our products are extremely complex, have numerous security-sensitive contact points in the system, and we've made some choices that do not match those of our competitors, often due to security concerns. Our refusal to treat chroot as a security tool is perhaps our most common source of "why don't you support this?" questions, and despite years of explaining our position, referencing numerous resources on the subject, providing examples of the futility of it, etc. doesn't make the question go away.
I think the best you can do is try to educate whenever the question comes up. It gets frustrating to answer the same question over and over again for years, especially if it's answered in the FAQ or documentation, but you pretty much just have to do it.
A much better way to respond to this request would be 'Yes! Here's a one time/time limited password generator that will do what you want'.
This is, of course, not possible in the general case. You can (sort of) do it for a specific site by changing the password and changing it back when you're done, which is what I ask people to do whenever they want me to poke around in their accounts. That obviously doesn't generalize across sites.
This entire idea of 'sharing a masked password' is completely ridiculous.
I know a lot of people who don't realize this.
(so if you could get past the screensaver you could in theory extract the creds from memory, but i don't know of a tool to do this and doing it by hand could be time consuming)
When I'm making online bank transfers, I get prompted for my password for every transfer, even though I'm already logged in - better to double-check the really sensitive stuff, rather than just protect the entry point.
For most people, having a password manager + random-generated passwords are _much_ better than using one simple password for all.
or how about browsers letting us know whether a bookmarklet is doing something suspicious?