Added on 08 Jul 2009(284 Views)
You might remember that about a week back Jacob Nielsen, one of the world’s leading experts on web usability, announced that the practice of password masking is detrimental to the overall user experience and is detrimental to security as well. As Nielsen put it, turning characters into bullets in the password field discourages the user from logging in, encourages the user to pick overly simple passwords, and is incredibly annoying when you make a mistake and have to retype the whole thing again because you can’t see where the error is.Jacob Nielsen also proposed that offering a checkbox would be a good idea for those situations when you really need to conceal your passwords, like when you are in an internet café, or working in an open plan office environment. Just tick the checkbox and your password is concealed. When there’s no one around and you feel safe about revealing your password, un-check the box.
As you would imagine, Jacob Nielsen’s words spurred much controversy amongst security experts – like for example Sophos’ Senior Technology Consultant Graham Cluley and Trend Micro’s Advanced Threat Researcher Ben April. They argued against Nielsen’s proposal, saying that dropping the practice of password masking would not be a good idea security-wise, would put you in socially awkward situations at times, and would send a bad message to the regular user. Graham Cluley also pointed out an essential flaw in Jacob Nielsen’s thinking: it is not the web page that masks passwords, it is the browser that does so.
At the time, the only one to support Jacob Nielsen was internationally renowned security technologist and author, Bruce Schneier. He agreed that since most times when you use the computer you are alone, then masking passwords is really nothing more than a nuisance and revealing them would prevent the user from making any mistakes. There are times when someone close to you will try to sneak a peak at your password, but shoulder surfing is not very common, added Schneier.
Now it seems that Bruce Schneier is taking back his words of support for dropping password masking: “So was I wrong? Maybe. Okay, probably. Password masking definitely improves security; many readers pointed out that they regularly use their computer in crowded environments, and rely on password masking to protect their passwords. On the other hand, password masking reduces accuracy and makes it less likely that users will choose secure and hard-to-remember passwords, I will concede that the password masking trade-off is more beneficial than I thought in my snap reaction, but also that the answer is not nearly as obvious as we have historically assumed.”
Previous articles on the subject:
Time to Drop Password Masking Expert Says
Security Experts Argue over Dropping Password Masking Proposal
Don't forget to:
RSSVia: www.schneier.com
Tags: Password, Password masking, Security, Usability
Link to this article:
Add comment:
Software News
Wolfram Alpha App 1.1 with Better Specialized Keyboards
The team behind computational knowledge engine Wolfram Alpha announced the release of an iPhone specific app last year, in October. The one thing that people complained about at the time...
09 Feb 2010
Linus Shows Nexus One Some Love, Google Shows Nexus One Users Some Love
Linus Torvalds, the father of Linux, says that when he got the original Google Phone, the G1, he was unimpressed. At the time Google gave him the device – that what I meant by “he got the G1”. Linus, who says...
09 Feb 2010
Google Superbowl Ad Draws Attention to the Need for Privacy
Back in January, on International Data Privacy Day, Mountain View-based search engine giant drew attention to its guiding privacy principles. In case you’re not familiar with...
09 Feb 2010
Free Software Alert: EASEUS Partition Master Professional Edition 5.0.1
The latest release of EASEUS Partition Master Professional Edition is version 5.0.1, and the company that developed the software is now giving it away for free. But you need to hurry up. This is a time limited offer...
09 Feb 2010
MSN Games and Windows Live Messenger Welcome FarmVille
The short description of FarmVille is this: “FarmVille is a game where you can farm with your friends.” Basically you get a plot of land and you have to plant crops, harvest them, make money to buy...
09 Feb 2010
Bill Cosby Is Not Dead, Just the Victim of Malware Spreaders
It’s the Kanye West and Johnny Depp story all over again. People with malicious intent have started a rumor that popular comedian and actor Bill Cosby, 72, died of natural causes, in his chair at home....
09 Feb 2010
Recommended Tools
Registry Booster 2010 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



