[prev in list] [next in list] [prev in thread] [next in thread] 

List:       kde-usability
Subject:    Re: Allowing No Hide mode in passwords
From:       Erik Hensema <erik () hensema ! net>
Date:       2004-01-19 9:54:14
Message-ID: 20040119095414.GA13202 () dexter ! home ! hensema ! net
[Download RAW message or body]

On Mon, Jan 19, 2004 at 12:44:36AM +0000, bj@altern.org wrote:
> First post to this list :-). As maintainer of KGpg, a user told me he was 
> using long passwords, and that it was hard to tell if he made a mistake 
> because currently KPasswordDialog only displays ************** when you type 
> a password. He would like to be able to actually see the password he is 
> typing. 
> 
> I think this could be a usability enhancement (for example for people that 
> have problem with typing) to allow the user to choose a "No Hide" mode from 
> the "passwords" module in the Control Center. In this "No Hide" mode, 
> passwords would appear in clear in the password dialogs.

I think having a password you can't type blindly is an insecure password.
We should be very careful not to encourage such behaviour.

It could however be a useful feature to be able to see the password as you
type. You also may want to consider to show only the last letter a user has
typed, or only the letter at the cursor. Hide the rest with stars.

Because of the insecurity a user should not be able to turn this feature on
before receiving some lecture on security and why this is a bad idea.

-- 
Erik Hensema (erik@hensema.net)
_______________________________________________
kde-usability mailing list
kde-usability@kde.org
https://mail.kde.org/mailman/listinfo/kde-usability
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic