Passwords are normally masked to prevent shoulder surfing, but the presumption is that the correct person is still at the keyboard. When you explicitly chose to show a password, the presumption is that you attempt to be aware of who is around you. If the bad guy is at the keyboard for your unlocked account, the fact is you've already lost.
> Yes, locking the account is the user's responsibility, but it wouldn't hurt to help them out, by not making it possible to view all a user's passwords in their chrome preferences.
This isn't about pushing responsibility off on the user. It's about not tricking users into believing they're safer than they actually are.
> Again, I'm aware that you could simply hop into keychain and check "show password", but this prompts for the user account password. At the very least, you should be doing the same.
If I'm an attacker, why would I use the keychain app to get Safari passwords? Just navigate to the site and change the auto-filled password field to text, or use an extension, or one of the many system-level approaches you have at your disposal. Many of these things are even available as tools that any novice can trivially acquire and use.