Why masking passwords isn't a good idea

 

Summary

A respected individual argued that password masking isn't worth the effort, even detrimental. Michael Kassner digs deeper to see if that's really the case.

Liked by

shangyilim July 28th, 2009

Events

IT Priorities 2010

Sydney, Australia - 27 Jul 2010
Melbourne, Australia - 28 Jul 2010
Mumbai, India - 4 Aug 2010
Delhi, India - 6 Aug 2010

IDC's Asia/Pacific Cloud Computing Conference 2010
31 Aug 2010

Marriott Hotel, Singapore

The article "Stop Password Masking", was written by Jakob Nielsen, a well-regarded expert on Web and user interfaces.

His profile states that he founded the "discount usability engineering" movement for fast and cheap improvements of user interfaces and has invented several usability methods, including heuristic evaluation. Nielsen holds 79 U.S. patents, mainly on ways of making the Internet easier to use.

As you can see by Nielsen's accreditation, his mentioning that using password masking is a bad idea isn't something to be taken lightly.

Why mask passwords?
Until I read the article, I considered masking passwords to be a no-brainer for the following reasons:

  • Masking passwords were the logical outcome of being concerned about people stealing passwords by visually observing the password being entered.
  • Auto-complete is a bad idea period, but masking helps prevent someone from seeing previous passwords that have the same first few characters. This is of special concern when the computer has multiple users.
  • Masking passwords is required by some regulatory bodies in order to gain their approval. Also a company's security policy may require masking any time a password is entered.

Why password masking is bad
Nielsen summarizes his stance by pointing out:

"Usability suffers when users type in passwords and the only feedback they get is a row of bullets. Typically, masking passwords doesn't even increase security, but it does cost you business due to log in failures."

Through his research, Nielsen has come to the conclusion that using nondescript bullets to cover up password characters violates an important usability principle, that of providing sensory feedback. To back up his claim, Nielsen provides some additional detail:

  • Users make more errors when they can't see what they're typing while filling in a form. They therefore feel less confident. This double degradation of the user experience means that people are more likely to give up and never log in to your site at all, leading to lost business.
  • The more uncertain users feel about typing passwords, the more likely they are to (a) employ overly simple passwords and/or (b) copy-paste passwords from a file on their computer. Both behaviors lead to a true loss of security.

I didn't see any reference to studies verifying either of the above theories, still both appear to have merit.

Using portable devices
I do agree with Nielsen about how masking passwords on mobile devices is a real pain. As proof, I know associates that do exactly as Nielsen mentioned above. They dumb-down the password just so it's easy to enter. Not a smart thing to do when visiting important Web sites such as a banking portal.

Another viewpoint
Jason Montgomery, a security expert with SANS presented a different viewpoint in this blog post. As a security aficionado, I was interested in his reply to something Nielsen had written.

I quoted it earlier, so here's a recap of the part being referred to:

"Typically, masking passwords doesn't even increase security, but it does cost you business due to log in failures."

Montgomery responded:

"Nielsen's probably right: It might be costing you business. The question is how much business? Security shouldn't be the be-all, end-all goal. It's there to serve the organization first and foremost. Viewing the cost of security controls with respect to the function it's protecting is the correct perspective.

I concur with Montgomery's approach and I'm sure Nielsen does as well. It's called compromise and I think that Nielsen may have already found a solution:

"Yes, users are sometimes truly at risk of having bystanders spy on their passwords, such as when they're using an Internet cafe. It's therefore worth offering them a checkbox to have their passwords masked; for high-risk applications, such as bank accounts, you might even check this box by default. In cases where there's a tension between security and usability, sometimes security should win."

Sounds like it might work, what do you think? Does it cover all possibilities? When do we know if we're safe enough to lower security standards for increased usability?

Final thoughts
Until I read Nielsen's blog post, I felt that masking passwords was just a necessary part of the process. Now I'm not so sure. It's cumbersome and businesses could be losing customers.

Yet on the flip side, not masking passwords is a potential security risk.

Disputes surrounding password usage continue to impress upon me the need for mainstream multifactor authentication. But wishful thinking doesn't help us right now. What's your take on yet another usability versus security conflict?

Michael Kassner has been involved with IT for over 30 years, and is currently a systems administrator for an international corporation and security consultant with MKassner Net.

Talkback

Why masking passwords isn't a good idea

It is a good idea. Masking requires improvement to alleviate usability issues associated with it. Do take a look at this view point! http://sanideos.blogspot.com/2009/06/my-answer-to-dr-norman-on-not-masking.html

San Ideos July 30th, 2009 Reply
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment
Access data anywhere in the private cloud & enable entirely new efficiencies with EMC VPLEX.
Tech Vendor: EMC

ZDNet Asia Live

Non-green IT products 'marketing suicide' http://bit.ly/aCqko4

Standards important for S'pore e-healthcare. http://bit.ly/dtC6Bn

RT @Droid_News: Motorola earnings beat expectations http://bit.ly/btsNAg | #Droid #Android

US court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4

great! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!

Shocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

Non-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4

Asian firms aware of IT snoops. http://bit.ly/9eGRxG

sg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps

Non-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD

Non-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4

1 hour 53 minutes ago by greentreats on topsy

Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs

@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com

RT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY

2 hours 50 minutes ago by phyllis777loves on topsy

RT @zdnetasia: 10 questions to ask when http://www.zdnetasia.c...

RT @zdnetasia: S'pore marketeers not chirping to Twitter's tune http://bit.ly/bF2aoa

Facebook led police to Philippine serial killer -- http://ow.ly/2iGnh

3 hours 6 minutes ago by hazelhassan on topsy

http://bit.ly/8v7Ov3 S'pore marketeers not chirping to Twitter's tune - ZDNet Asia http://is.gd/dSngs

4 hours 59 minutes ago by easytweeting on topsy

in the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/

5 hours 30 minutes ago by findpdf on Researchers find workaround for Adobe PDF fix

Just want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...

5 hours 37 minutes ago by winsource on Making the case for Filipino IT entrepreneurship

Hi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks

2 days 30 minutes ago by Pacific Time Pte Ltd on Recycle your HP print cartridges and get rewards

Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...

2 days 36 minutes ago by yedwin on iPhone 4 shows prudence in procrastination

While I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...

2 days 47 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastination

The online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)

2 days 45 minutes ago by mingnow on iPhone 4 to ring in Singapore on Friday

After an awful silence, finally the prices are out..

3 days 41 minutes ago by melvinchia on iPhone 4 to ring in Singapore on Friday

Glad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...

3 days 47 minutes ago by gnome_refugee on Smitten with Xfce 4

yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...

3 days 46 minutes ago by ggolemg on Smitten with Xfce 4

@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...

3 days 52 minutes ago by fredericmuller on Taobao initiates Chinese open source revolution

Geez. I would think giving free books and getting kids to school would be a better place to start.

3 days 59 minutes ago by mingnow on India's US$35 tablet--how low can it go?

I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...

4 days 46 minutes ago by mingnow on Taobao initiates Chinese open source revolution

hey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...

4 days 16 minutes ago by wendy on iPhone 4 shows prudence in procrastination

It could be done without all these. Just use the opacity addon of Compiz.

4 days 40 minutes ago by hariks0 on How to get RGBA support in Ubuntu