9 ms·
I'm honestly seeing little value in asterisks with WFH and the move to passphrases. Feedback is important when you're typing a long phrase with complete precis
by letsdothisagain 3y ago
I'm honestly seeing little value in asterisks with WFH and the move to passphrases. Feedback is important when you're typing a long phrase with complete precision. Plus shoulder surfing is simply not a thing when my physical security profile now involves a locked front door and a call to the police.
- iknowstuff 3y agoAre you describing your experience or implying that the industry should change this because you can WFH?
- froggit 3y agoThe latter. They seemingly meant "I can WFH, so asterisks are meaningless to everyone. F@&# asterisks!"
- autoexec 3y agoWFH also means Working From my backyard, the coffee shop around the corner, the library, a friend's house, a hotel room, etc. Even for people who only work at home while working remotely, private homes can see a lot of traffic. I wouldn't assume all screens are kept and used in totally secure environments so we should probably still stick with masked passwords and telling users not to keep passwords written on a post-it note stuck to their monitor.
- deleted 3y ago[deleted]
- aeternum 3y agoAnd now employees simply leave their laptop open with the SSH window up while getting their coffee because it's now so annoying to close the lid and correctly type the password. >USB Rubber Ducky has entered the chat
- matt-attack 3y agoIf they can see the screen wouldn’t they be better off just looking at the keyboard to directly observe what’s being typed?
- jgalt212 3y ago> the coffee shop around the corner I would hope people in high leverage job roles would just avoid such behavior.
- froggit 3y ago> I would hope people in high leverage job roles would just avoid such behavior. I used to hope that as well. Then I met people and lost that hope. It's truly impressive how much stupid shit gets pulled by people that "should know better."
- wizofaus 3y agoYou've never typed a password in while screen sharing?
- kelnos 3y agoOh god no, absolutely not. Always stop sharing for the duration of the password entry.
- axus 3y agoSadly I think security systems will have to accommodate the possibility that someone else can see your screen. And hope that they can't see your keyboard.
- wizofaus 3y agoWhat if you're demonstrating a problem with a login screen? And yes, I've had to do exactly that more than once. I wouldn't do it with a particularly sensitive password (online banking etc) but there are enough passwords I use regularly for work purposes where it wouldn't be a significant risk for others to watch me type it in, certainly if the characters aren't revealed at all while typing. Though having password fields be able to detect your screen is being shared automatically and obscure what pixels are relayed would be nice.
- jrockway 3y agoWhy use a good password while testing your login screen? I use "iamroot" and "password".
- wizofaus 3y agoThey're typically passwords that are only for testing accounts anyway, and that are known to the team members I'm sharing with. But...it's easy to slip up now and then and forget you're actually putting in a password while screen sharing that it's probably best not to have your co-workers know! Obviously the worst is your actual O/S password, as knowing that could potentially allow a co-worker access to other passwords that are quite sensitive, but I'm not sure it's even possible to screen share your O/S login screen - probably shouldn't be! It is a good argument for not re-using that password for any browser-based logins, but SSO policies tend to make that impossible unfortunately. Mind you I use a pin for my O/S login screen, whereas for browser-based logins you can't.
- koheripbal 3y agoPlenty of value in confirming that you are hitting each key exactly once.
- EGreg 3y agoWhy not just mutate a specific fixed-length line with every keypress?
- glaucon 3y ago> I'm honestly seeing little value in asterisks They're essential ! How else would we encourage the average user to use as short and and as simple a password as they can get away with ?