I don't understand why you would have a problem with this. The javascript that makes this happen, does run in the browser, on your desktop, or as you put it, the application level. Regardless of how your password is displayed when typed (either plaintext, starred, or a combo), the value of the field is sent as plain text to the web server (if not ssl). This demo attempts to solve the problem of shoulder surfing vs usability, not building a more secure login mechanism.