Added on 29 Jun 2009(313 Views)
Every time you want to access your email account, instant messaging client, even log into your operating system, you have to provide a user name and a password. While the username is clearly visible, the password is always displayed as a long list of * characters. Replacing characters with bullets is a practice called password masking, and has been around for quite some time now. According to Jakob Nielsen, one of the world’s leading experts on web usability, it is about time this practice is dropped.Jakob Nielsen argues that the practice of hiding characters behind bullets, as is the case with passwords, is in fact hurting web usability. The user enters his password, and the only feedback he receives is a row of bullets – which personally I find terribly annoying as I never know where I misspelled by password and consequently have to delete it all and start from scratch, making the login process a terrible bother. Besides being annoying, password masking is not even that secure, says Nielsen.
“It's time to show most passwords in clear text as users type them. Providing feedback and visualizing the system's status have always been among the most basic usability principles. Showing undifferentiated bullets while users enter complex codes definitely fails to comply. Most websites (and many other applications) mask passwords as users type them, and thereby theoretically prevent miscreants from looking over users' shoulders. Of course, a truly skilled criminal can simply look at the keyboard and note which keys are being pressed. So, password masking doesn't even protect fully against snoopers,” says Nielsen.
The practice of password masking has two direct effects on the end user. First of all he is more prone to make errors while typing in the password simply because he can’t see what he is typing – making said user feel less confident as Nielsen put it, and think twice about login in. Secondly, the user will be tempted to either user overly simple passwords, or just copy/paste the password from a locally stored file – both practices are very wrong, security-wise.
“Users are sometimes truly at risk of having bystanders spy on their passwords, such as when they're using an Internet café,” added Nielsen. "It's therefore worth offering them a checkbox to have their passwords masked; for high-risk applications, such as bank accounts, you might even check this box by default. In cases where there's a tension between security and usability, sometimes security should win. In most cases, however, users will appreciate getting clear-text feedback as they enter passwords. Your business will increase, and security will even improve a tiny bit as well.”
For the Firefox user that does not want to mask his password, there is a simple solution: the Show Passwords add-on. What this add-on does is eliminate those annoying * symbols and let you see exactly what you are typing into the password field. And if at any time you feel the need to once again mask your password, Show Passwords can be easily turned on and off by clicking on the icon placed in the Firefox Status Bar.
If you would like to get Show Passwords, a download location is available here.
Don't forget to:
RSSTags: Password, Password masking, Security, Usability
Link to this article:
Comments
rudranarayan - 29 Jun 2009 14:09
this is a great antivirus
Add comment:
Software News
Chromium OS Goes Open-Source
This summer Google let the world know that it is working on a new operating system meant for the user that spends most of his time online. The operating system – aptly named Chrome OS because it is a natural extension...
20 Nov 2009
Office 2010 Beta Downloads Available to the Public
Earlier this week Redmond-based software giant Microsoft announced that Office 2010 became available for download as a Beta. The catch was that only ...
20 Nov 2009
Mozilla Releases: Firefox 3.6 Beta 3
The development process of the Firefox 3.6 browser is moving along rapidly. The first Beta version was released at the start of the month; Beta 2 was released about two weeks after Beta 1. About a week has passed since...
20 Nov 2009
New Labs Feature for Gmail: Green Robot!
The software developers at Google have announced the release of a new Gmail Labs offering called Green Robot! This new offering is meant to improve the Gmail Chat user experience by letting the ...
20 Nov 2009
Opera Mobile 10 Beta for Windows Mobile Is Out Also
Opera Software, the company that we all know for making the innovative and feature rich Opera web browser, has released Opera Mobile 10 Beta for Windows Mobile-powered devices. This release follows in the...
19 Nov 2009
Beta Testing is Over, Stable Version of Trillian for iPhone Released
The focus so far has been on desktop version of this multiprotocol instant messaging software application, Trillian Astra (version 4.1). Today is time to switch focus away from the desktop version and onto something a bit more...
19 Nov 2009
Recommended Tools
Registry Booster 2010 Enhanced, deeper and faster error scan performance. Now also in 5 languages! Free Scan
Driver Scanner 2009
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
Fast and easy, it boosts performance by scanning for, downloading & installing driver updates
SpeedUpMyPC 2009
How fast is your PC really running? Turbo-charge your Internet and PC performance here
How fast is your PC really running? Turbo-charge your Internet and PC performance here



