Hacker News new | past | comments | ask | show | jobs | submit login

Technically passwords that should be retrieved at a later date are stored using two-way encryption. So the thing is, the passwords are always "visible", as they're retrievable. Removing the "Show" button is not really making things more secure as it is retrievable using other means. This is same with all browsers that save passwords.

You could lock it away with a one-way encrypted password but the problem with that is it's just "theatrics", giving a false sense of security... the stored passwords are still two-way encrypted either way, or else they can't be retrieved for later use. That means it is just as breakable as if they weren't. Once the hacker finds the password database on your computer it should be considered compromised.

If you don't trust your browser or your computer then you should use a service like LastPass or 1Password, i.e. if you consider them trustworthy to handle your passwords and if you're not on an insecure WIFI network. There is really no other way around it.

I do agree though that all browsers should be more clear about it... unfortunately it's not particularly easy to explain computer security to a user who is not a computer science nerd.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: