<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: New in the Lab: HalfMask &#8211; a Password Masking Experiment</title>
	<atom:link href="http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/</link>
	<description>Web Application Design &#38; Development</description>
	<lastBuildDate>Fri, 03 Feb 2012 03:55:36 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Brian</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-10043</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Tue, 14 Jun 2011 11:24:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-10043</guid>
		<description>Hi,
nice post, you&#039;ve done a great job for this article. It,s a very an elegant technical solution .
Thank you for this informations 
Sincerely

&lt;a href=&quot;http://www.gutlin.com/&quot; rel=&quot;nofollow&quot;&gt;&lt;strong&gt;Antique Clocks&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;&lt;/strong&gt;</description>
		<content:encoded><![CDATA[<p>Hi,<br />
nice post, you&#8217;ve done a great job for this article. It,s a very an elegant technical solution .<br />
Thank you for this informations<br />
Sincerely</p>
<p><a href="http://www.gutlin.com/" rel="nofollow"><strong>Antique Clocks</strong></a><strong></strong></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1289</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Thu, 07 Jan 2010 00:26:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1289</guid>
		<description>While this is an elegant technical solution I think you&#039;re going down the wrong path. The issue I see is that every website that uses the un/pw model follows a different standard which forces each person to come up with variations of the same password. In the end a user should be able to arrive at a website and using visual cues on the site be able to easily remember a password that is unique to that website. For example, I create unique passwords for each site using the first and last letters of the website. Only I know what words equate to the letters so it&#039;s pretty secure as long as I don&#039;t use a commonly used set of words as my  secret words. It&#039;s about 90% effective and I have about 50 unique passwords.</description>
		<content:encoded><![CDATA[<p>While this is an elegant technical solution I think you&#8217;re going down the wrong path. The issue I see is that every website that uses the un/pw model follows a different standard which forces each person to come up with variations of the same password. In the end a user should be able to arrive at a website and using visual cues on the site be able to easily remember a password that is unique to that website. For example, I create unique passwords for each site using the first and last letters of the website. Only I know what words equate to the letters so it&#8217;s pretty secure as long as I don&#8217;t use a commonly used set of words as my  secret words. It&#8217;s about 90% effective and I have about 50 unique passwords.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patxi</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1281</link>
		<dc:creator>Patxi</dc:creator>
		<pubDate>Mon, 04 Jan 2010 14:08:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1281</guid>
		<description>Brilliant idea!

I&#039;d love to have HashMask as a &#039;Firefox Extension&#039;, and activate it either on all my password fields or only on a subset.

This way, this would not be depending on the host, but on my machine.

Congrats!</description>
		<content:encoded><![CDATA[<p>Brilliant idea!</p>
<p>I&#8217;d love to have HashMask as a &#8216;Firefox Extension&#8217;, and activate it either on all my password fields or only on a subset.</p>
<p>This way, this would not be depending on the host, but on my machine.</p>
<p>Congrats!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Rubin</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1214</link>
		<dc:creator>Bill Rubin</dc:creator>
		<pubDate>Thu, 03 Dec 2009 21:12:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1214</guid>
		<description>I never type passwords on web pages.  Never.  I always use a password manager, which copies passwords (and userids too) into the appropriate fields, usually with just a short, fixed keystroke sequence.  Never having to type a password means that all passwords can by cryptic, long, and distinct from each other.  
The whole concept of passwords that you manually type in yourself suffers from major security issues in real-world usage.  As Bruce Schneier has written (Secrets &amp; Lies), the vast majority of users choose weak passwords, and then reuse them, share them, and write them on a Post-it.  Using a password manager mitigates all these problems:  Even the user has no need to know his passwords, because he never types them.
Full disclosure:  I&#039;m associated with the KeePass Password Manager project (free, open source), and have written a plugin for it.</description>
		<content:encoded><![CDATA[<p>I never type passwords on web pages.  Never.  I always use a password manager, which copies passwords (and userids too) into the appropriate fields, usually with just a short, fixed keystroke sequence.  Never having to type a password means that all passwords can by cryptic, long, and distinct from each other.<br />
The whole concept of passwords that you manually type in yourself suffers from major security issues in real-world usage.  As Bruce Schneier has written (Secrets &amp; Lies), the vast majority of users choose weak passwords, and then reuse them, share them, and write them on a Post-it.  Using a password manager mitigates all these problems:  Even the user has no need to know his passwords, because he never types them.<br />
Full disclosure:  I&#8217;m associated with the KeePass Password Manager project (free, open source), and have written a plugin for it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robin Laur</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1089</link>
		<dc:creator>Robin Laur</dc:creator>
		<pubDate>Tue, 14 Jul 2009 09:13:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1089</guid>
		<description>Interesting response to Nielsen&#039;s latest Alertbox! You might want to include some (more?) uppercase characters in the masking to improve masking or uppercase/numeral/symbol characters. Also, space characters will look different when masked since there is no visible character to mask.
One idea you might want to test is to incorporate the password masking method Nokia uses with their &quot;smart&quot; phones, which is to display the last input character and replace it with a bullet after a timeout or when the next character is pressed. Show the last character (masked) only until the next is pressed or until a timeout. Then replace it either with a mess of characters or with a bullet. This would give a possible shoulder surfer less time to read the password.
~llaur</description>
		<content:encoded><![CDATA[<p>Interesting response to Nielsen&#8217;s latest Alertbox! You might want to include some (more?) uppercase characters in the masking to improve masking or uppercase/numeral/symbol characters. Also, space characters will look different when masked since there is no visible character to mask.<br />
One idea you might want to test is to incorporate the password masking method Nokia uses with their &#8220;smart&#8221; phones, which is to display the last input character and replace it with a bullet after a timeout or when the next character is pressed. Show the last character (masked) only until the next is pressed or until a timeout. Then replace it either with a mess of characters or with a bullet. This would give a possible shoulder surfer less time to read the password.<br />
~llaur</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stephan Wehner</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1088</link>
		<dc:creator>Stephan Wehner</dc:creator>
		<pubDate>Mon, 13 Jul 2009 01:51:57 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1088</guid>
		<description>Tom wrote in a previous comment:
&quot;Very thoughtful though. I like that you even thought out basic copy/paste security!&quot;
Not sure what this basic security is. Here with Firefox 3.0.11 I&#039;m seeing
1. When pasting only the first letter is obscured.
2. It is possible to select the whole password, copy, and then paste to recover it without any obfuscation.
Doesn&#039;t look like basic security to me.
I don&#039;t find it easy to recognize what I typed. Still a nice idea!
Stephan</description>
		<content:encoded><![CDATA[<p>Tom wrote in a previous comment:<br />
&#8220;Very thoughtful though. I like that you even thought out basic copy/paste security!&#8221;<br />
Not sure what this basic security is. Here with Firefox 3.0.11 I&#8217;m seeing<br />
1. When pasting only the first letter is obscured.<br />
2. It is possible to select the whole password, copy, and then paste to recover it without any obfuscation.<br />
Doesn&#8217;t look like basic security to me.<br />
I don&#8217;t find it easy to recognize what I typed. Still a nice idea!<br />
Stephan</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1087</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Thu, 09 Jul 2009 14:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1087</guid>
		<description>It&#039;s a nice idea, but it&#039;s kind of like one of those Magic Eye books. Once you figure out how to focus your eyes the correct way, the password is fairly easy to see.
If this technique gained widespread adoption, I think people&#039;s eyes would become trained to see the password more and more easily and eventually it would even fail the over-the-shoulder test.
Very thoughtful though. I like that you even thought out basic copy/paste security!</description>
		<content:encoded><![CDATA[<p>It&#8217;s a nice idea, but it&#8217;s kind of like one of those Magic Eye books. Once you figure out how to focus your eyes the correct way, the password is fairly easy to see.<br />
If this technique gained widespread adoption, I think people&#8217;s eyes would become trained to see the password more and more easily and eventually it would even fail the over-the-shoulder test.<br />
Very thoughtful though. I like that you even thought out basic copy/paste security!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doug</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1086</link>
		<dc:creator>Doug</dc:creator>
		<pubDate>Thu, 09 Jul 2009 13:10:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1086</guid>
		<description>Nice work Chris! I don&#039;t think Nielsen has completely thought through the implications of his proposal, but regardless, HalfMask is a nice option for certain situations.</description>
		<content:encoded><![CDATA[<p>Nice work Chris! I don&#8217;t think Nielsen has completely thought through the implications of his proposal, but regardless, HalfMask is a nice option for certain situations.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rpcutts</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1085</link>
		<dc:creator>rpcutts</dc:creator>
		<pubDate>Thu, 09 Jul 2009 06:50:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1085</guid>
		<description>..it&#039;s like typing when drunk.</description>
		<content:encoded><![CDATA[<p>..it&#8217;s like typing when drunk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve</title>
		<link>http://blog.arc90.com/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1084</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Thu, 09 Jul 2009 05:10:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.daniell.acr90-dev-02/2009/07/08/new-in-the-lab-halfmask-a-password-masking-experiment/#comment-1084</guid>
		<description>When I press Command, a letter appears in the password box.  When I release it, it goes away.
This seems weird, and Control/Shift/Option don&#039;t do this.</description>
		<content:encoded><![CDATA[<p>When I press Command, a letter appears in the password box.  When I release it, it goes away.<br />
This seems weird, and Control/Shift/Option don&#8217;t do this.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

