3 ms·
Your two points are related: because the password is masked and you can't see what you're typing to spell-check, it's worth asking the user to type the password
by adnrw 13y ago
Your two points are related: because the password is masked and you can't see what you're typing to spell-check, it's worth asking the user to type the password again to make sure they spelled it correctly the first time.
That being said, I completely agree with you – I don't think there's much validity in masking the password field except maybe when it's auto-filled by the browser.
We have tested turning off the masking on various sites we've developed and in general users tend to freak out and think the site is insecure as a result.
- chinpokomon 13y agoYup, makes perfect sense to me why that design doesn't go over for a public accustomed to seeing the password mask. It would be neat if that could be a preference set in the OS for power users, but I can see that being abused and I see it no way compatible with legacy sites and applications. You couldn't make it the default, because it drops a degree of security for all users of the OS. And it wouldn't get adopted widely enough for it to be worth the effort, being more expensive to support for developers.