On 12/22/25 2:52 AM, Robert Elz wrote:
     Date:        Sun, 21 Dec 2025 13:23:29 -0800
     From:        Bruce Jerrick <[email protected]>
     Message-ID:  <[email protected]>

   |     I don't think it would "rarely" be used.  It would be a good thing
   |     to have when reading a password.

Displaying anything while reading passwords is a security problem,
it makes it too easy for someone who can, even just briefly, observe
the screen, to determine how many characters long the password is.

The most useful iterations of this strategy deliberately display a
different number of characters than are actually input. Of course,
without a toggle to make the password visible, however briefly, that
strategy hurts users who are not sure how many characters they entered.

--
``The lyf so short, the craft so long to lerne.'' - Chaucer
                 ``Ars longa, vita brevis'' - Hippocrates
Chet Ramey, UTech, CWRU    [email protected]    http://tiswww.cwru.edu/~chet/

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to