orangy
If there is an account associated with <your email> you will receive an email with a link to reset your password.This doesn’t give potential attacker any information if the address is registered or not. But what would be a proper error message for when you register new account and email is already there?
karelpeeters
08/29/2017, 7:41 AMlovis
08/29/2017, 7:43 AMlovis
08/29/2017, 7:46 AMkarelpeeters
08/29/2017, 7:46 AMlovis
08/29/2017, 7:48 AMlovis
08/29/2017, 7:49 AMkarelpeeters
08/29/2017, 7:50 AMkarelpeeters
08/29/2017, 7:51 AMlovis
08/29/2017, 7:51 AMkarelpeeters
08/29/2017, 7:52 AMPassword masking has proven to be a particularly nasty usability problem in our testing of mobile devices, where typing is difficult and typos are common. But the problem exists for desktop users as well.
lovis
08/29/2017, 7:52 AMkarelpeeters
08/29/2017, 7:52 AMlovis
08/29/2017, 7:53 AMlovis
08/29/2017, 7:54 AMlovis
08/29/2017, 8:04 AM>> Offer the option of showing passwords in clear. However, unmasking does not need to be the default for login. Although we advocated for this practice for a long time, only recently sites and apps have started adopting it, and some users can feel unsecure when seeing the password characters in clear. That is why, at this stage, we recommend masking the password by default and presenting users with a Show password checkbox that allows them to unmask it.
lovis
08/29/2017, 8:04 AMkarelpeeters
08/29/2017, 8:05 AMorangy
evanchooly
08/29/2017, 8:37 AMkarelpeeters
08/29/2017, 8:37 AMevanchooly
08/29/2017, 8:38 AMtipsy
08/29/2017, 8:54 AM@lovis it’s like 99% of the time nobody is actually watching you while you enter your passwordif you don't mask, some mobile keyboards will store and predict your password
lovis
08/29/2017, 8:58 AMtextVisiblePassword
nothing will be stored/predicted (actually, that’s the only thing that works for all manufacturers! 🙄 )tipsy
08/29/2017, 9:05 AM<input>
elements, the article seemed to be discussing web rather than nativetipsy
08/29/2017, 9:05 AMlovis
08/29/2017, 9:06 AMbamdmux
08/29/2017, 9:07 AMbamdmux
08/29/2017, 9:08 AMbamdmux
08/29/2017, 9:09 AMbamdmux
08/29/2017, 9:09 AMtipsy
08/29/2017, 9:11 AMbamdmux
08/29/2017, 9:11 AMbamdmux
08/29/2017, 9:17 AMkarelpeeters
08/29/2017, 9:18 AMbamdmux
08/29/2017, 9:19 AMbamdmux
08/29/2017, 9:19 AMbamdmux
08/29/2017, 9:20 AMbamdmux
08/29/2017, 9:21 AM