I would certainly be hesitant to type my password on a website which is handling the field like that. Let the browser vendors implement this option at the application level (as an option, probably, so users can enable/disable on all websites).
I would certainly be hesitant to type my password on a website which is handling the field like that. Let the browser vendors implement this option at the application level (as an option, probably, so users can enable/disable on all websites).
But there is an issue even if the implementation is totally seamless and bug-free. Maybe one site implements this slightly differently, and maybe some sites have a checkbox to clear the mask, or other sites show me each character for a fixed delay (e.g., character disappears after 250 ms or something), etc. In each case I must make some accomodations to how I expect a password field to behave. On the other hand if it is at the application level then there is opportunity to evolve the feature uniformly across all websites--and also give the user a single option which controls the behavior.