Bug 959463 - please don't put focus in password box unexpectedly
Summary: please don't put focus in password box unexpectedly
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: anaconda
Version: 19
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Anaconda Maintenance Team
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-05-03 14:51 UTC by Andre Robatino
Modified: 2013-05-06 21:14 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2013-05-06 21:14:22 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Andre Robatino 2013-05-03 14:51:36 UTC
Description of problem:
There is a recent anaconda change such that the password is displayed in plain text when focus is in the password box - explained in https://bugzilla.redhat.com/show_bug.cgi?id=958608#c5 . This sounds reasonable if the user actually intends to have focus in that box. Not so much if it's unexpected. For example:

1) User is installing F19. Says to coworker, please turn around so I can enter my password, this will only take a few seconds.
2) Enters password twice. Unfortunately, it's detected as weak and when user clicks Done, the focus goes unexpectedly back into the password box, revealing it. Some inconspicuous text saying that the password is weak and that one has to click Done *again* for it to take appears all the way at the bottom of the window, where user isn't looking. User spends about half a minute before figuring out what happened, and in the confusion forgets to tell coworker to stay turned around. Password is visible the whole time.
3) After about 15 seconds, coworker assumes user is done, turns around, sees password.

Lesson to take away - focus in the password box needs to be intentional, otherwise telling someone to look away temporarily doesn't work so well.

Version-Release number of selected component (if applicable):
anaconda 19.23-1, I think (version in 19 Beta TC2)

How reproducible:
always

Comment 1 Chris Lumens 2013-05-06 21:14:22 UTC
I'm just going to back the original root password stuff out, so this will not be necessary.  Hold on a minute.


Note You need to log in before you can comment on or make changes to this bug.