# Interface issue resulting in revealing passwords

**URL:** https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914
**Category:** UX
**Created:** [May 9, 2020, 3:38pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914 "2020-05-09T15:38:51Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![yaxu](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yaxu/32/178942_2.png) [@yaxu](https://meta.discourse.org/u/yaxu)
#### Post date: [May 9, 2020, 3:38pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914/1 "2020-05-09T15:38:51Z")

</div>

Noticing a lot of people stating their pronouns in their introductory post, I added a ‘pronouns’ profile field:

 ![image](https://global.discourse-cdn.com/meta/original/3X/5/f/5fbe83a1fedd092c05c50a3a33b73c405cd664f6.png)

However maybe you already see the issue - people are used to giving their password twice on such forms.. and five people already did exactly that, putting their password in the ‘pronouns’ field! I’m now in the process of wiping this field for those affected and notifying them of the potential breach..

I’m not sure what interface tweaks would get around this problem. Maybe putting the password field last, or putting a divider around it? I’m going to try renaming the field so it looks less like “Password”..

---

<div class="post-metadata">

### Author: ![seanblue](https://avatars.discourse-cdn.com/v4/letter/s/dc4da7/32.png) [@seanblue](https://meta.discourse.org/u/seanblue)
#### Post date: [May 9, 2020, 3:56pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914/2 "2020-05-09T15:56:51Z")

</div>

Do they not notice that their password is in plaintext in the pronouns field?

---

<div class="post-metadata">

### Author: ![yaxu](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yaxu/32/178942_2.png) [@yaxu](https://meta.discourse.org/u/yaxu)
#### Post date: [May 9, 2020, 4:19pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914/3 "2020-05-09T16:19:13Z")

</div>

Evidently not. This is a forum for people who perform live coded music using programming languages, they can be pretty fast typists.

---

<div class="post-metadata">

### Author: ![Canapin](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/canapin/32/119591_2.png) [@Canapin](https://meta.discourse.org/u/Canapin)
#### Post date: [May 9, 2020, 4:43pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914/4 "2020-05-09T16:43:41Z")

</div>

As you said, I’d rename the field to something less similar than “P[something]” and separate it from the mandatory fields with a bit of css (adding an horizontal line or something like that).

Or maybe make the field a list with predefined choices so people won’t use the field for something else.

---

<div class="post-metadata">

### Author: ![yaxu](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/yaxu/32/178942_2.png) [@yaxu](https://meta.discourse.org/u/yaxu)
#### Post date: [May 9, 2020, 5:32pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914/5 "2020-05-09T17:32:25Z")

</div>

Ok will try that and keep an eye on it.

If this is not too uncommon an issue, I feel the best general solution would be to put the password field last.

---

<div class="post-metadata">

### Author: ![maiki](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/maiki/32/233950_2.png) [@maiki](https://meta.discourse.org/u/maiki)
#### Post date: [May 9, 2020, 6:53pm UTC](https://meta.discourse.org/t/interface-issue-resulting-in-revealing-passwords/150914/6 "2020-05-09T18:53:50Z")

</div>

Change the field label to, “I like to be called…” or “You may refer to me by…” and keep the descriptive text.
