# Users entering passwords in the custom user field

**URL:** https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123
**Category:** UX
**Created:** [2017 年6 月 26 日 14:26 UTC](https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123 "2017-06-26T14:26:12Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![SlyRemarks](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/slyremarks/32/80816_2.png) [@SlyRemarks](https://meta.discourse.org/u/SlyRemarks)
#### Post date: [2017 年6 月 26 日 14:26 UTC](https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123/1 "2017-06-26T14:26:12Z")

</div>

We’ve noticed something interesting and a bit concerning on our Discourse: users are entering their passwords on an user field we’ve added. Basically, it is really helpful for our community that users share their location, it makes supporting them much easier. Therefore when they sign up they are asked for this information so others, especially the moderators, have an easier job (so the information needs to be publicly visible). Because this field is placed directly beneath the password field, and on a lot of sites you’re asked to confirm the password, users automatically write their passwords twice without really reading the description.

We’ve changed the style-sheet so that the user field is more distinctive and have reworded it too. Ideally the password would be the last field, not the field we’ve added. Have I missed something, is there a way to do this?

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [2017 年6 月 26 日 18:11 UTC](https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123/2 "2017-06-26T18:11:18Z")

</div>

I am not sure I agree about moving it to the end, but totally acknowledge something is off and by default we should do a better job.

We could automatically detect people entered the password in a non password field and stop all progress till they amend it.

---

<div class="post-metadata">

### Author: ![Mittineague](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mittineague/32/114259_2.png) [@Mittineague](https://meta.discourse.org/u/Mittineague)
#### Post date: [2017 年6 月 26 日 18:15 UTC](https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123/3 "2017-06-26T18:15:18Z")

</div>

Would a horizontal rule or fieldsets work well enough?

---

<div class="post-metadata">

### Author: ![erlend\_sh](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/erlend_sh/32/119475_2.png) [@erlend\_sh](https://meta.discourse.org/u/erlend_sh)
#### Post date: [2017 年6 月 27 日 08:08 UTC](https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123/4 "2017-06-27T08:08:47Z")

</div>

I’m not aware of any issues, but those using auto fill tools should also test this and make sure we’re not confusing any robots.

---

<div class="post-metadata">

### Author: ![fefrei](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fefrei/32/119538_2.png) [@fefrei](https://meta.discourse.org/u/fefrei)
#### Post date: [2017 年6 月 27 日 09:01 UTC](https://meta.discourse.org/t/users-entering-passwords-in-the-custom-user-field/65123/5 "2017-06-27T09:01:09Z")

</div>

> [@sam](#):
>
> We could automatically detect people entered the password in a non password field and stop all progress till they amend it.

This sounds like a _very_ good idea. There is no good reason users should echo their password (or anything very similar) in any other field…
