Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

(Never enter your real password into a password checker

In their defense, it's stated pretty clearly that you shouldn't enter your real password and that this website allows you to test the "type of passwords" you use.

They could use the fact that it's over HTTP to teach a second lesson in the results page about HTTP vs HTTPS, and warn the user again that he/she should stopping using that password immediately.



If the sentence you quoted were the one that they used, I would agree with you that it was stated clearly. Unfortunately, they chose to word it this way:

"(Never enter your real password into a password checker, as unlike this one, some may be fake)"

The sentence is parenthetical, undermining it's importance, and it goes in two different directions, which makes it hard to follow. They should clearly advise users against entering their "real" password in one sentence, and then attest to the authenticity of their password checker in a separate sentence.

By the end of their sentence, it's hard to tell whether they mean that I shouldn't put my "real" password into other password checkers. The implication is that their password checker is real and safe. A clearer way to phrase it would be like this:

"Don't put your real password into this password checker."


But their reasoning for not entering your real password into a checker is "...unlike this one, some may be fake"

Then they follow it up with "Why not get your family, friends and workmates to test their passwords too?"

And the placeholder in the input field is "Enter your password".


And immediately after they tell you not to enter your real password, they say "Why not get your family, friends and workmates to test their passwords too?"


It's implied at first glance that it's for testing your password though.

Most people wouldn't even know the mistake they've made and are probably sending the results link on too.


Not very clearly. Most people would read over that sentence (I did at first, although I of course wouldn't dream of entering my real password into that site). It should at least be displayed in bold red.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: