Schneier says he was 'probably wrong' on masked passwords
theregister.co.uk
theregister.co.uk
Designers have to be aware that in some browsers there'll be a checkbox next to password fields.
I'm pretty sure you can implement something like this on the web with some simple javascript, dynamically changing the input type from "text" to "password" and vice versa.
Or you can put this option in menu or status bar or whatever.
By the way, I don't understand your complaints about design and layouts. I've never had problems with designing forms. Maybe this is because I didn't try to replace native controls with some uber-fancy things? (which is a good thing)
Web forms are where the usability rubber hits the road online. When adding an item to your form you should always be of the mind set that this extra step (optional or not) will lose you conversions, but you have to have it because of X. This forces you to justify placing item X, which in this case is the unmask password option. Is having an option to unmask the password field going to gain you more conversions than not? I have no data, just anecdotes and experience, but those all tell me no.
Putting a check box next to the entry field is putting GUI decisions on your user because you can't figure it out, and it will lose you conversions.
EDIT: Re-reading this it sounds like personal attack on the OC. It's not. I'm using the universal you.
The problem of displaying passwords has been solved by Unix years ago: do not show any visual feedback whatsoever. Security over convenience.
The problem of storing and subsequent input of random secure passwords has also been solved by Schneier and others via pwsafe and variants thereof. No worries about mistyping at all.
For special cases like Blackberry-type gadgets, what is needed is simply a port of pwsafe.
Given this fact, it's not too hard to see why he would have come out against masking . . .
I blogged about this here: http://is.gd/1wVja
Because... the credit card numbers are also clear text.
People on HN, for example, will have a freakout about the password but never the credit card number. It's extremely unusual to shield a credit card number on entry, because of mistakes.
We chose to treat passwords the same way.
I mean, sometimes you _really_ are alone, with nobody shoulder surfing, and password masking is damned annoying. So, why not a check-box to turn masking off? And for the paranoid/security conscious, we can default mask on.
Think: "Middle Path".
"Mask-on by default" means no regular user will ever uncheck. I think you greatly overstimate people's security knowledge, not to mention UI.
By default, the masking would be enabled. All you see are "*".
If however, you have some nasty password and you are in a safe location, you can do_action and turn off stars to "12345".
As a security expert, you should provide what's more secure, even if that means recognizing the users are too dumb to follow your rules.
We're into untested territory thinking here, and I don't believe calling for statistics will disprove anyone. In the absence of hard numbers, I take your challenge.
staunch, I bet you $25 (via PayPal) that two users will not uncheck password masking off, when presented with an explanation what it's for, without looking either to the left, right or behind before typing the password.
I'll probably try this on one of my sites (I've tried no masking before). Maybe I'll blog it. You can keep your $25.
So what is the harm there? Even if a user could not figure out (oddly) what the checkbox does, he'll continue to get the password field to behave in the way he is accustomed to.
Surely, people will have trouble figure out the purpose of the checkbox in the beginning. But that's how things tend to be when you run into something for the first time. It takes some time before a style becomes standard.