On 26/02/15 12:03 AM, Christopher Karlof wrote:
Who freaked out?  This sounds like pre-Mozilla, but was it
developers/managers/etc, or was it user?

It was non-Mozilla. We received a lot of support requests that suggested
what we were doing were doing was wrong. I don't know if it necessarily is,
but I will admit is jarring to see your password appear in the clear when
you've had 10+ years of conditioning that it always appears as ***** (on
the Web) or not all at (in *nix).

Relevant exchange between Jacob Neilsen and Bruce Schneier a few years ago.

Neilsen's take: http://www.nngroup.com/articles/stop-password-masking/

Schneier's: https://www.schneier.com/blog/archives/2009/06/the_problem_wit_2.html

And some commentary from Out-Law.com with a follow up from Schneier: http://www.out-law.com/page-10152

Seems like things have changed a bit since 2009 when those articles were written.

Cheers, Jamon
_______________________________________________
Dev-fxacct mailing list
[email protected]
https://mail.mozilla.org/listinfo/dev-fxacct

Reply via email to