Yahoo! & Sprint Displayed Passwords at Scale. What Happened?

I published on article outlining how we show passwords on our new mobile app, Polar. Mike Lee shared what Yahoo! learned when they did something similar. Thanks for the info Mike!

  1. @lukew when I was at Y! We eliminated the second input field and displayed the full password prior to form submission. Eavesdropping unlikly
  2. @lukew the rationale was that the user should have more control to physically protect view of the PW. Make the overall form shorter / easier
  3. @lukew We saw double digit improvements in the overall flow, but that was also influenced by other changes to the form. No security issues.
  4. @lukew and by improvements I mean on overall reg conversion. We also eliminated dependency on proprietary ID and allowed mobile # as the ID.
  5. First time I removed masking/dupes was Sprint All 20mm customers needed new pswd (CPNI). Success, NO issues. Tested, well-measured. @lukew
  6. Did this years ago for /desktop/ web with no security issues and /huge/ proven usability success. Required for mobile!!! @tkadlec @lukew
  7. @tkadlec @lukew Lots of clients worry about negative security perception from users when showing passwords…
  8. @tkadlec @lukew We rolled it out for a large client recently & had zero negative feedback from either user test participants or live users.
  9. I forgot to link to my pattern on signon for mobile. Large portion is/assumes not masking, explains issues 4ourth.com/wiki/Sign%20On @lukew
  10. This is such a simple and elegant fix to a UX problem we all deal with - mobile passwords. From @lukew: http://www.lukew.com/ff/entry.asp?1653

Did you find this story interesting? or comment as 4 already did!

Liked!

Luke Wroblewski

Digital product design & strategy guy in Silicon Valley, CA. Author of Web Form Design & Site Seeing. Currently CPO and co-founder of Bagcheck.

Total views
4,190

Storify

@Storify