Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


July 09, 2008

User Names and Passwords in Authentication Forms

RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

I made an interesting observation today regarding login forms that accept user names and passwords for authentication--and what I'm seeing makes no sense.

Here's the issue: Nearly every login form that I've ever seen requires someone to enter their user name in clear text while the password is obscured so that anyone looking at the screen can't see the actual password. That latter aspect makes good sense.

So why don't application developers (including desktop, server, and Web developers) cause the user name field to also be obscured? After all, if someone can type a password without seeing the actual letters then they can also type a user name without seeing the letters.

I think the answer boils down to "follow the leader." What I mean by that is that somewhere along the line of system evolution someone made the decision to not obscure user names but to definitely obscure passwords. Then, probably 99% of everyone else who ever designed a login screen followed that lead--for no apparent reason other than simply mimicking what had already been done in the past. Whatever the reason they certainly weren't thinking about how to improve security while designing the form fields.

If the standard advice is to never let anyone know your user name and password, and to never write that information down, then why let people type it in clear text in plain view of anyone that can see the computer screen? Doing so makes no sense to me.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.





Search Security Matters
 
Security Matters
SEPTEMBER 2008
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30     
or

 Recently in Security Matters
Four Security Patches From Microsoft In September
Make a Comment
Google Chrome - Yawn
Make a Comment
Securify Headed To Secure Computing
Make a Comment
W32.Gammima Worm Goes Into Orbit
Make a Comment
IE 8 Beta 2 Ready
Make a Comment

More blogs about technology,
software, and Windows.

ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Interested in Email Encryption?
Read about the advantages of identity-based encryption in this free report.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing