Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> 1.) typing it out manually while you can't see if you made a mistake

This is my pet peeve. Password fields should not be obfuscated by default. It should be a toggle that is off on page load. Shoulder surfing is a corner case.



Cameras are everywhere in public spaces, and most people wouldn't notice a password field wasn't obfuscated until they've already started typing. Defaulting to obfuscated seems the only sensible option.


But with a camera I can just see what you typed, with a fairly high accuracy.


Video, yes. Stills, seems less likely.


Are there /any/ digital cameras these days that only do stills?


No way. The number of reported cases of passwords being stolen simply by physical proximity is enough to make this a sensible default. I agree that there should be an option to show the password as you're typing or, at a minimum, once you're done typing (less secure) but making that the default is unreasonable.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: