Terrible Password Security Advice From Jakob Nielsen
chriskite.com
chriskite.com
Reset buttons might not be, but password masking sure is. There's nothing quite as startling as seeing your password in plaintext. Not having the bullets is just going to make you look insecure, and appearances matter in the psychology of security. You don't want your users feeling insecure.
Even if this wasn't a daft idea, he's beginning to contradict himself, anyway:
It's therefore worth offering them a checkbox to have their passwords masked
contradicts his claim on his "Reset buttons must die" piece:
The extra choice requires extra thinking, and the time saved by using an optimal interaction technique is often smaller than the time wasted on having to think instead of just moving ahead with a single interaction technique that is always used.
So for all the time you save by seeing your password in the clear, you lose by having to deal with the extra checkbox.
Also worth noting: browsers have autofill these days. Just loading a page on one of these browsers would be enough to disclose your passwords. Forget shoulder surfing, just create a diversion, browse to a few sites on the victim's computer, and you've got the lot.
Edit > Preferences > Security > Saved Passwords > Show Passwords > Yes
Lists all my saved passwords in cleartext.
Why oh why can't we just carry around certs on USB fobs? Isn't it the future yet?
I'm pretty sure there's no easy way to make it the default behavior, but you're just 2 clicks away from having it on the page you're viewing.
These users are often more likely to use a less secure password in visible prompts out of fear of compromising their more secure ones.
Second, it would have to be supported at the browser level well enough to be at least as easy as password usage, which is hard, since password usage is super-easy, as long as you choose a weak one (and people avoid sites that enforce good passwords, if they can). I'm using Safari, and I can't find anything about client-side certificates in the prefs. I know IE and Firefox support them fairly well, as I've used them for intranet sites in the past, but I don't think it's easy. Basically, the first time a site demanded a cert, the browser would have to walk someone through generating one, and it's hard to see how that could be made easy enough for people to sit through it.
Third, any cert that has a password to unlock is going to be at least as difficult for the user as just using a password, and any cert which doesn't require a password will be vulnerable to being stolen by trojans, etc.
You can get all the good things about using a cert by just making your site SSL-only and using a cookie, and this also avoids some of the bad things (inconvenience), but not all (vulnerability to trojans).
It's frustrating to mistype a password and not realize it, sure, but it's much, much worse to have your password fall into the wrong hands just because someone happened to look at your screen at the right moment.
<input type="password" follow="1"/>
Then, when I type in my password, it will show your password as stars, but with the last 'follow' number of characters in plain-text... like:
Follow of 1: * * * * * * * a
Follow of 3: * * * * * tra
I prefer the OSX wifi password dialog, with a checkbox to show the password that's off by default.
1.Right click
2.View Page Info
3.Click on Security Tab
4.Click on View Saved Passwords