Hacker News new | ask | show | jobs
by glaucon 57 days ago
Stop masking passwords by default.

Masked passwords were boring when passwords were typically 'goeagles' but now they're 'Justlongenough22!' they're a real barrier to anybody who doesn't type the string multiple times a day.

If you really think that someone staring over the users shoulder is a genuine risk factor than allow people to turn it on, not (if the user is lucky) allow them to turn it off.