Added on 01 Jul 2009(298 Views)
We recently reported that the practice of replacing characters with bullets when the user types in his password has a negative impact on the overall user experience and does not provide much in terms of security. The one to argue this point of view is Jakob Nielsen, one of the world’s leading experts on web usability, who said that masking passwords has two direct effects: it makes the user more prone to make a mistake while typing the password and it makes the user pick an overly simple password. According to Jakob Nielsen, the practice of masking passwords by default should be dropped and replaced with something else – like a checkbox. “It's time to show most passwords in clear text as users type them. Providing feedback and visualizing the system's status have always been among the most basic usability principles. Showing undifferentiated bullets while users enter complex codes definitely fails to comply. Users are sometimes truly at risk of having bystanders spy on their passwords, such as when they're using an Internet café. It's therefore worth offering them a checkbox to have their passwords masked; for high-risk applications, such as bank accounts, you might even check this box by default,” said Nielsen.
At the time Nielsen said this, the only one to agree with him was internationally renowned security technologist and author, Bruce Schneier (and me, for the simple reason that typing in stuff that you do not see is terribly annoying and I have to keep my eyes on the keyboard to make sure I do not make a mistake). According to Schneier, passwords should be made visible on your personal computer since almost every time you use it you are alone. There is of course the chance that someone might look over your shoulder when you type in your password, but this means password masking is compromised (said Nielsen), not to mention that it is something that rarely happens (said Schneier).
Senior Technology Consultant with Sophos, Graham Cluley does not agree with dropping password masking, nor does he agree with Schneier’s claim that “shoulder surfing” (the practice of looking over someone’s shoulder to see what he’s typing) is very rare. Graham Cluley argues that in an open plan work environment, anyone could snoop on your password. On top of that, when you want to quickly access your email account from a friend’s house, ticking a mask password checkbox would create social friction.
“What happens when I am at a friend's house and I want to quickly log in to my web email account to forward him something I have been discussing with him? Sure, he's my friend and I trust that he's not going to misbehave - but I really don't think I should be sharing my password with him. Equally I don't want to be put in the awkward social position of going to the extra effort of ticking a box to obscure my password from him. Much better that I had no option to see the password at all,” says Graham Cluley.
Cluley goes on to say that Nielsen and Schneier are both wrong about one thing: it is not “most websites” that hide passwords, it is the browser that does so. It is the browser that interprets the HTML of the site and obscures the password field. “If there were an option to display password input fields as cleartext rather than asterisks, then that should be set in the user's browser not decided by individual websites,” added Cluley. “Even then, I can't imagine many situations when it wouldn't actually be more of an inconvenience (asking friends and colleagues to turn around or wear a bucket over their head for the next ten seconds) than the masking of passwords we have at the moment.”
Trend Micro’s Advanced Threat Researcher Ben April, while agreeing that shoulder surfing compromises password security and password masking has a negative impact on usability, says that dropping the practice would not benefit the user, security-wise. According to Ben April, password masking has “zero value” if you are dealing with a seasoned attacker, but when you are dealing with a newbie wrongdoer he “will be looking at the screen when you start entering your password” and “by the time they realize their mistake, they will only see *** and have already missed a good portion of your password.” There is one other advantage that password masking brings to the table, April says; it gets you to remember passwords. When you type in the same password day in and day out you will get so proficient that your fingers will type in incredibly fast.
“My main objection to the demise of password masking is the message that it sends to casual users. We enter a case of do-as-I-say-not-as-I-do. How can we ask our users to secure their password reminders if the entire password appears clear as day on the screen every time they enter it? Masking a password sends the message to the user that it is important that they not share their passwords, that they should not even show these to you, reinforcing the never-give-out-your-password tenet. In many cases, masking discourages copying and pasting passwords though only through naïveté,” says Ben April.
Don't forget to:
RSSTags: Password, Password masking, Security, Usability, Sophos, Trend Micro
Link to this article:
Add comment:
Software News
Fun Friday Feature: Cry Translator iPhone App
I remember that some obscure school teacher once told me that speech separates man from beast. Now I always found that reasoning to be somewhat flawed. What about parrots? They can speak – sort of. Or...
06 Nov 2009
Chrome 3.0 and 4.0 Updated on the Stable and Dev Channel
The guys over at Google are keeping as busy, of not more so, as the guys over at Mozilla. While the Mozilla Foundation has recently released Firefox 3.6 Beta 1 and Firefox 3.5.5, Mountain View-based search engine giant Google ...
06 Nov 2009
November 09 Patch Tuesday: 6 Security Bulletins, 15 Vulnerabilities
Next week’s first two days are already booked. On Monday, the 9th of November, we will be celebrating Firefox’s 5th anniversary. On Tuesday, we will focus on something less entertaining, mainly patching our...
06 Nov 2009
Firefox 3.5.5 Update Released
The Mozilla Foundation has released another update for its browser, mainly Firefox 3.5.5. The update follows in the footsteps of Firefox 3.5.4, an update that was released about a week back...
06 Nov 2009
iTunes 9.0.2 Update Loves Apple TV 3.0 Software, Breaks Palm Pre Syncing (Again)
Cupertino-based software developer Apple has recently updated its digital media player iTunes to version 9.0.2. The update, which follows in the footsteps of iTunes 9.0.1 and iTunes 9.0, brings forth one significant new change...
05 Nov 2009
Blacksn0w: Unlock Tool for the iPhone 3G and 3GS
Great news for iPhone 3G and iPhone 3GS users that updated the device to baseband version 05.11; or iPhone 3G and iPhone 3GS users that bought the device with an updated baseband. Original iPhone hacker...
05 Nov 2009
Recommended Tools
Registry Booster 2009
Clean, Repair and Optimize your PC with the #1 industry leading and award-winning utility
Clean, Repair and Optimize your PC with the #1 industry leading and award-winning utility
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



