Non-green IT products 'marketing suicide' http://bit.ly/aCqko4
23 minutes ago by MatthewLinkedIn on twitterZDNet is available in the following editions:
A respected individual argued that password masking isn't worth the effort, even detrimental. Michael Kassner digs deeper to see if that's really the case.
password, jakob nielsen, internet, internet cafe, michael kassner
The article "Stop Password Masking", was written by Jakob Nielsen, a well-regarded expert on Web and user interfaces.
His profile states that he founded the "discount usability engineering" movement for fast and cheap improvements of user interfaces and has invented several usability methods, including heuristic evaluation. Nielsen holds 79 U.S. patents, mainly on ways of making the Internet easier to use.
As you can see by Nielsen's accreditation, his mentioning that using password masking is a bad idea isn't something to be taken lightly.
Why mask passwords?
Until I read the article, I considered masking passwords to be a no-brainer for the following reasons:
Why password masking is bad
Nielsen summarizes his stance by pointing out:
"Usability suffers when users type in passwords and the only feedback they get is a row of bullets. Typically, masking passwords doesn't even increase security, but it does cost you business due to log in failures."
Through his research, Nielsen has come to the conclusion that using nondescript bullets to cover up password characters violates an important usability principle, that of providing sensory feedback. To back up his claim, Nielsen provides some additional detail:
I didn't see any reference to studies verifying either of the above theories, still both appear to have merit.
Using portable devices
I do agree with Nielsen about how masking passwords on mobile devices is a real pain. As proof, I know associates that do exactly as Nielsen mentioned above. They dumb-down the password just so it's easy to enter. Not a smart thing to do when visiting important Web sites such as a banking portal.
Another viewpoint
Jason Montgomery, a security expert with SANS presented a different viewpoint in this blog post. As a security aficionado, I was interested in his reply to something Nielsen had written.
I quoted it earlier, so here's a recap of the part being referred to:
"Typically, masking passwords doesn't even increase security, but it does cost you business due to log in failures."
Montgomery responded:
"Nielsen's probably right: It might be costing you business. The question is how much business? Security shouldn't be the be-all, end-all goal. It's there to serve the organization first and foremost. Viewing the cost of security controls with respect to the function it's protecting is the correct perspective.
I concur with Montgomery's approach and I'm sure Nielsen does as well. It's called compromise and I think that Nielsen may have already found a solution:
"Yes, users are sometimes truly at risk of having bystanders spy on their passwords, such as when they're using an Internet cafe. It's therefore worth offering them a checkbox to have their passwords masked; for high-risk applications, such as bank accounts, you might even check this box by default. In cases where there's a tension between security and usability, sometimes security should win."
Sounds like it might work, what do you think? Does it cover all possibilities? When do we know if we're safe enough to lower security standards for increased usability?
Final thoughts
Until I read Nielsen's blog post, I felt that masking passwords was just a necessary part of the process. Now I'm not so sure. It's cumbersome and businesses could be losing customers.
Yet on the flip side, not masking passwords is a potential security risk.
Disputes surrounding password usage continue to impress upon me the need for mainstream multifactor authentication. But wishful thinking doesn't help us right now. What's your take on yet another usability versus security conflict?
Michael Kassner has been involved with IT for over 30 years, and is currently a systems administrator for an international corporation and security consultant with MKassner Net.
Non-green IT products 'marketing suicide' http://bit.ly/aCqko4
23 minutes ago by MatthewLinkedIn on twitterStandards important for S'pore e-healthcare. http://bit.ly/dtC6Bn
31 minutes ago by zdnetasia on twitterRT @Droid_News: Motorola earnings beat expectations http://bit.ly/btsNAg | #Droid #Android
46 minutes ago by frogiss117 on twitterUS court rejects class action status for Intel antitrust suit http://bit.ly/9AbnMF
1 hour 7 minutes ago by MLMRocketFuel on twitterNon-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/aCqko4
1 hour 11 minutes ago by greenexistence on twittergreat! US court rejects class action status for Intel antitrust suit http://bit.ly/9acwER Good day!
1 hour 12 minutes ago by bestwinnernet on twitterShocked! RT: @danielgoh: Oh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs
1 hour 15 minutes ago by mitchtan on twitterNon-green IT products 'marketing suicide': By Munir Kotadia, ZDNet Australia on July 30, 2010 (8 minutes ago) Vend... http://bit.ly/aCqko4
1 hour 26 minutes ago by OutsourceMethod on twittersg marketeers not chirping to twitter's tune http://bit.ly/aRAa1Y - baby steps baby steps
1 hour 38 minutes ago by sashizoso on twitterNon-green IT products 'marketing suicide': This 50-hectare eco-business park is described as a "living laboratory"... http://bit.ly/cEkDUD
1 hour 39 minutes ago by BlissfulSeed on twitterNon-green IT products 'marketing suicide': At the same time, it seems vendors see green technology as a very high ... http://bit.ly/aCqko4
1 hour 53 minutes ago by greentreats on topsyOh really? RT @scoopsg: (zdnetasia) S'pore marketeers not chirping to Twitter's tune http://scoo.ps/dpkySs
2 hours 6 minutes ago by danielgoh on twitter@mrcolinlim but of course for more tech updates you can always visit zdnetasia.com
2 hours 32 minutes ago by t_phuck on twitterRT @zdnetasia: Searchable Facebook user data posted to Pirate Bay http://bit.ly/ciJQxY
2 hours 50 minutes ago by phyllis777loves on topsyRT @zdnetasia: 10 questions to ask when http://www.zdnetasia.c...
3 hours 10842 seconds ago by Zoomicon on twitterRT @zdnetasia: S'pore marketeers not chirping to Twitter's tune http://bit.ly/bF2aoa
3 hours 5 minutes ago by ellsetan on twitterFacebook led police to Philippine serial killer -- http://ow.ly/2iGnh
3 hours 6 minutes ago by hazelhassan on topsyhttp://bit.ly/8v7Ov3 S'pore marketeers not chirping to Twitter's tune - ZDNet Asia http://is.gd/dSngs
4 hours 59 minutes ago by easytweeting on topsyin the mean time, if you need to find PDF eBooks, you may use http://www.findpdf.us/
5 hours 30 minutes ago by findpdf on Researchers find workaround for Adobe PDF fixJust want to say what a great blog you got here! My appreciation of your work, cause i am an IT student also. Try this one too, http://w...
5 hours 37 minutes ago by winsource on Making the case for Filipino IT entrepreneurshipHi, We have ton of HP empty cartridges. Could you collect them in our office??
Thanks
Thanks Kenneth, for your insights. Good to know people out there can see the issue for what it is, and to do so impassively, that is. ...
2 days 36 minutes ago by yedwin on iPhone 4 shows prudence in procrastinationWhile I agree that the issues with the device have raised many an eyebrow, I think it's unwise to forget that many phone reviews have...
2 days 47 minutes ago by kennethkoh on iPhone 4 shows prudence in procrastinationThe online apple store http://store.apple.com/ is not available now. Maybe it's updating the pricing ;)
2 days 45 minutes ago by mingnow on iPhone 4 to ring in Singapore on FridayAfter an awful silence, finally the prices are out..
3 days 41 minutes ago by melvinchia on iPhone 4 to ring in Singapore on FridayGlad you discovered the Xfce 4.6 magic. Its other endearing feature is its phenomenal configurability. You can make the desktop look and ...
3 days 47 minutes ago by gnome_refugee on Smitten with Xfce 4yep, tried them all and xfce with compiz/emerald instead of fvwm is by far the best experience I've had. If you didn't know ther...
3 days 46 minutes ago by ggolemg on Smitten with Xfce 4@mingnow: why do you think so? How do you think the FOSS community could tackle this issue? I'm involved in a lot of efforts to get t...
3 days 52 minutes ago by fredericmuller on Taobao initiates Chinese open source revolutionGeez. I would think giving free books and getting kids to school would be a better place to start.
3 days 59 minutes ago by mingnow on India's US$35 tablet--how low can it go?I think it's great the that country with the biggest internet population is finally contributing back to the open-source world. I thi...
4 days 46 minutes ago by mingnow on Taobao initiates Chinese open source revolutionhey.there Im Wendy from a PR Agency.I find your blog interesting and well written.In days to come,we would hold an event. Therefore We ...
4 days 16 minutes ago by wendy on iPhone 4 shows prudence in procrastinationIt could be done without all these. Just use the opacity addon of Compiz.
4 days 40 minutes ago by hariks0 on How to get RGBA support in UbuntuStop Waiting Start Switching to Juniper
Free Gartner Report shows it reduces costs and increases efficiency
What makes a hospital a smart hospital?
Download your copy of 'The Smart Hospital' Resource Kit to learn more
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
Why masking passwords isn't a good idea
It is a good idea. Masking requires improvement to alleviate usability issues associated with it. Do take a look at this view point! http://sanideos.blogspot.com/2009/06/my-answer-to-dr-norman-on-not-masking.html