Usually this guy's observations are spot on, but this is just wrong. For instance, every time I give a presentation I usually have to login to a secure site. I'm almost always plugged into an overhead projector while I'm logging in.
So, not only is this guy suggesting websites change their technology, he's also suggesting users modify their behavior to be more secure.
It's just too easy to screw that up and despite the argument proferred there is no real benefit. If typing on mobile devices is hard it doesn't seem what we need to do is post our credit card numbers online.
I used to work as phone support for a webapp targeted at Real Estate Agents. 60% of our web + phone support requests were related to passwords. A third of those requests were errors due to misspellings.
An option to reveal the text of the password field would have a drastic effect on these support requests. It would lower calls and call times on these issues. Even if this 15-minute change only saved 30 minutes of support time a -year- this would be a net win.
You might not screw up passwords, but plenty of people do. I'm not suggesting to have it permanently visible, just the option to make it visible. This enables people with password issues to debug their own issues before resorting to a password reset or contacting support.
I liked the part where he neglected to mention any possible benefit of the current arrangement or the fact that many of us have no problem with actually being required to type well and remember stuff.
You mean where he says "Yes, users are sometimes truly at risk of having bystanders spy on their passwords, such as when they're using an Internet cafe.... In cases where there's a tension between security and usability, sometimes security should win."?
Typos happen even to those who can type well. And I can remember my password, but sometimes it's a matter of figuring out which password to remember. If the one I expected to work doesn't, it just be that I unknowingly mistyped it, not that it was the wrong password.
So, not only is this guy suggesting websites change their technology, he's also suggesting users modify their behavior to be more secure.
Not going to happen.