# Seeing online passwords

**URL:** <https://boards.straightdope.com/t/seeing-online-passwords/743151>\
**Category:** Factual Questions\
**Created:** [January 14, 2016, 5:31pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151 "2016-01-14T17:31:08Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 14, 2016, 5:31pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/1 "2016-01-14T17:31:08Z")

</div>

My computer remembers my passwords for some sites. That’s good, because I don’t have to type them in. On the other hand, sometimes I forget them. (I tend to use different passwords instead of the same one over and over.) Some sites will give me a hint and/or email me my password. Other sites require that I provide a new password. I don’t like that.

Is there a way to see the password that my computer is storing for a website? I’m using OS X 10.9.5 and Safari 9.0.1.

---

<div class="post-metadata">

**Author:** ![vd](https://avatars.discourse-cdn.com/v4/letter/v/b19c9b/32.png) [@vd](https://boards.straightdope.com/u/vd)\
**Post date:** [January 14, 2016, 5:46pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/2 "2016-01-14T17:46:17Z")

</div>

If it’s showing you the asterisks, there’s [this](http://lifehacker.com/5946529/easily-reveal-hidden-passwords-in-any-browser) method.

In Safari, you might have to enable the developer menu first.

---

<div class="post-metadata">

**Author:** ![TimeWinder](https://avatars.discourse-cdn.com/v4/letter/t/bcef8e/32.png) [@TimeWinder](https://boards.straightdope.com/u/TimeWinder)\
**Post date:** [January 14, 2016, 5:50pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/3 "2016-01-14T17:50:41Z")

</div>

> [@Johnny\_L.A](#):
>
> Is there a way to see the password that my computer is storing for a website? I’m using OS X 10.9.5 and Safari 9.0.1.

There’s two ways it might be being stored.

The browser may be storing it, in which case you want to go to Preferences… -\> Passwords tab and click the “Show Passwords for Selected Sites” box.

Alternatively, the OS might be storing it (they overlap somewhat), in which case you want to run “KeyChain Access” (in your /Applications/Utilities folder), which can show you your stored passwords. K.A. is a little bit of a mess–it has a whole bunch of different functions, many of them complicated–but poke around in it for a while and you’ll probably see what you need.

---

<div class="post-metadata">

**Author:** ![Defensive\_Indifference](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/defensive_indifference/32/6502_2.png) [@Defensive\_Indifference](https://boards.straightdope.com/u/Defensive_Indifference)\
**Post date:** [January 14, 2016, 5:54pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/4 "2016-01-14T17:54:33Z")

</div>

You can try one of these two methods:

> **[How to See your Passwords Hidden Under Asterisks - Digital Inspiration](https://www.labnol.org/internet/reveal-hidden-password/25600/)**
>
> Tech, a la carte

> **[Seeing hidden passwords in a browser takes a few simple steps](https://www.usatoday.com/story/tech/columnist/komando/2014/05/23/seeing-hidden-passwords-in-a-browser/9259431/)**
>
> It's handy to have your browser store passwords, but take care with these steps.

> [@Johnny\_L.A](#):
>
> Some sites will give me a hint and/or **email me my password**.

My bold. This makes me sad. It means the site is storing your password in plain text, which is wrong on many levels. I’m a security guy, and one time an organization that _issues information security credentials_ emailed me my password in plain text. Kind of killed whatever credibility they may have had (which honestly wasn’t much to begin with).

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 14, 2016, 5:57pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/5 "2016-01-14T17:57:52Z")

</div>

> [@vd](#):
>
> If it’s showing you the asterisks, there’s [this](http://lifehacker.com/5946529/easily-reveal-hidden-passwords-in-any-browser) method.

Gods, I _hate_ those long-ass ads you can’t skip!

I tried searching for ‘input type=password’, but it doesn’t find it.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 14, 2016, 6:00pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/6 "2016-01-14T18:00:34Z")

</div>

> [@TimeWinder](#):
>
> The browser may be storing it, in which case you want to go to Preferences… -\> Passwords tab and click the “Show Passwords for Selected Sites” box.

There we go. Right password, wrong cases.

Thanks.

---

<div class="post-metadata">

**Author:** ![Mijin](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mijin/32/9369_2.png) [@Mijin](https://boards.straightdope.com/u/Mijin)\
**Post date:** [January 14, 2016, 6:08pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/7 "2016-01-14T18:08:53Z")

</div>

While we’re on the subject, it’s annoying that all the browsers I’m using just store usernames and passwords as a one-to-one mapping across all sites.

So, say two web pages require my user name to be my email address. I use the same e-mail account for both but (rightly) decide to use a different password.  
Since the browser can only map one user name to one password it’s constantly filling in the wrong password and/or asking me to update the reference.

It might be because I’m using older versions of Chrome / Firefox / Opera / IE…if one of the updates fixes that, that might actually be worth updating for…

---

<div class="post-metadata">

**Author:** ![TimeWinder](https://avatars.discourse-cdn.com/v4/letter/t/bcef8e/32.png) [@TimeWinder](https://boards.straightdope.com/u/TimeWinder)\
**Post date:** [January 14, 2016, 6:33pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/8 "2016-01-14T18:33:28Z")

</div>

> [@Johnny\_L.A](#):
>
> There we go. Right password, wrong cases.

When I’m King, one of my first acts will be the “passwords are a SEQUENCES OF KEY PRESSES, and the state of caps/lock (or shift except as a key that can be pressed in the sequence) should be irrelevant under pain of death” law.

Seriously, it’s 2016 and we’re still rejecting passwords because of caps lock being down?

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [January 14, 2016, 6:49pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/9 "2016-01-14T18:49:00Z")

</div>

> [@TimeWinder](#):
>
> Seriously, it’s 2016 and we’re still rejecting passwords because of caps lock being down?

Passwords should have a mixture of cases.

---

<div class="post-metadata">

**Author:** ![GusNSpot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gusnspot/32/436_2.png) [@GusNSpot](https://boards.straightdope.com/u/GusNSpot)\
**Post date:** [January 14, 2016, 7:21pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/10 "2016-01-14T19:21:36Z")

</div>

Thumb scan would be better.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [January 14, 2016, 7:41pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/11 "2016-01-14T19:41:33Z")

</div>

**Mijin** , Firefox has stored passwords separately for separate sites for ages now. It also no longer asks you if you want to change the stored password until after it submits it to the site so you can see if it worked. I expect all modern browsers do this, too, but I don’t have experience with them.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [January 15, 2016, 2:09am UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/12 "2016-01-15T02:09:02Z")

</div>

> [@TimeWinder](#):
>
> When I’m King, one of my first acts will be the “passwords are a SEQUENCES OF KEY PRESSES, and the state of caps/lock (or shift except as a key that can be pressed in the sequence) should be irrelevant under pain of death” law.
> 
> Seriously, it’s 2016 and we’re still rejecting passwords because of caps lock being down?

You won’t be king long after all the security disasters that silly policy causes.

The problem now is passwords are too easy, not that they’re too hard.

---

<div class="post-metadata">

**Author:** ![Heracles](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/heracles/32/487_2.png) [@Heracles](https://boards.straightdope.com/u/Heracles)\
**Post date:** [January 15, 2016, 12:10pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/13 "2016-01-15T12:10:15Z")

</div>

> [@TimeWinder](#):
>
> When I’m King, one of my first acts will be the “passwords are a SEQUENCES OF KEY PRESSES, and the state of caps/lock (or shift except as a key that can be pressed in the sequence) should be irrelevant under pain of death” law.
> 
> Seriously, it’s 2016 and we’re still rejecting passwords because of caps lock being down?

But, but, Sire, the keys I press are vastly different between my desktop PC, my Surface tablet, my Android tablet and my phone. And each of these has French and English keyboard layouts installed. On Windows, the # symbol is Shift-3 in English but has its own unshifted key in French. It’ll never fly, Sire.

---

<div class="post-metadata">

**Author:** ![jtur88](https://avatars.discourse-cdn.com/v4/letter/j/e9c0ed/32.png) [@jtur88](https://boards.straightdope.com/u/jtur88)\
**Post date:** [January 15, 2016, 1:04pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/14 "2016-01-15T13:04:03Z")

</div>

In Firefox, go to Tools \> Options \> Security \> Saved passwords \> Show passwords.

I assume there is a similar lookup path in other browsers. It’s the browser that saves the passwords.

---

<div class="post-metadata">

**Author:** ![pulykamell](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pulykamell/32/3166_2.png) [@pulykamell](https://boards.straightdope.com/u/pulykamell)\
**Post date:** [January 15, 2016, 1:57pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/15 "2016-01-15T13:57:52Z")

</div>

> [@TimeWinder](#):
>
> When I’m King, one of my first acts will be the “passwords are a SEQUENCES OF KEY PRESSES, and the state of caps/lock (or shift except as a key that can be pressed in the sequence) should be irrelevant under pain of death” law.
> 
> Seriously, it’s 2016 and we’re still rejecting passwords because of caps lock being down?

Passwords absolutely should be case-sensitive.

What pisses me off is the various password-making “rules” that exist across sites. Some require at least one uppercase. Some don’t. Some need a number. Some don’t. Some need a special character/punctuation. Some need a special character, but only from a small subset of special characters. Some just used to reject any special character at all. It drives me batty.

---

<div class="post-metadata">

**Author:** ![Melbourne](https://avatars.discourse-cdn.com/v4/letter/m/b5e925/32.png) [@Melbourne](https://boards.straightdope.com/u/Melbourne)\
**Post date:** [January 15, 2016, 9:09pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/16 "2016-01-15T21:09:37Z")

</div>

> [@Johnny\_L.A](#):
>
> Passwords should have a mixture of cases.

Even better, passwords should have a mixture of **BOLD** and _italic_ cases.

---

<div class="post-metadata">

**Author:** ![gazpacho](https://avatars.discourse-cdn.com/v4/letter/g/6f9a4e/32.png) [@gazpacho](https://boards.straightdope.com/u/gazpacho)\
**Post date:** [January 15, 2016, 9:23pm UTC](https://boards.straightdope.com/t/seeing-online-passwords/743151/17 "2016-01-15T21:23:03Z")

</div>

> [@Melbourne](#):
>
> Even better, passwords should have a mixture of **BOLD** and _italic_ cases.

And at least one character in comic sans.
