Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One thing to note is that pretty much every other password field shows length, and the fact that sudo is so much more paranoid reminds me of this XKCD: https://xkcd.com/1200/

Seriously, what does sudo even protect anymore, and when are you typing it with someone looking over your shoulder?

If you have a Linux or Mac desktop, the login password prompt has the same design choice regarding showing characters and is much more likely to actually be used in front of someone. In modern Linux development, you shouldn’t be using sudo most of the time, and on ssh machines, you shouldn’t have a sudo password.

And even if someone did see it then they’d have to get physical access to your machine. If someone has easy physical access to your machine and wishes you harm, then knowing the length of your desktop login is probably the least of your worries.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: