Option to general disable the function "Show password" ?

Implemented

Option to general disable the function "Show password" ?

avatar

Hello together,

we use RDM Enterprise with MS-SQL-Database.

Is there an option to disable "show password" even for Administrators and even when it's the own password from the "personal credentials" ?


Best regards
Joerg

All Comments (4)

avatar

Hello,

There is currently no option to achieve this. We have opened a ticket to add a GPO.

Just to be sure, by "show password", do you mean the "View Password" button, or the little 'eye' to "reveal password", or both? Could you give a screenshot of what you would like to disable exactly?

Regards,

Hubert Mireault

avatar

Hello Hubert,

thank you for your feedback.

For explanation: We use the software in a team and have defined our servers including the logins. There are servers, where the login is done with a general system-user, the password of these accounts is known by all IT-employees, so thats not a problem..

But there are several servers, where each IT-employee use his own personal credentials for server-login. In the session-definition whe have defined "use my personal login information". And here is the problem: If you leave your computer unlocked, another person could easily check out your password by using the function "Show password" for a session-defintion. (Yes, we have a clean desk policy, and yes, you can lock the application itselfe, but nevertheless this is a security issue. E.g. in Windows itselfe you can't see your password anywhere in clear text.)






And yes, also in the own credentials section, it should be possible to deactivate the "eye" function






In other words: Don't show the personal login-credentials in clear-text at any place in the software


It would rise the securty, if this could be implemented.

Thank you very much in advance for checking this.


Best regards
Joerg

2020-08-03_140505.png

2020-08-03_140036.png

avatar

Thank you for the detailed description of your scenario. From what you describe, the best way we can make the GPO would be to disable all View Password / Reveal Password prompts, for administrators and non-administrators. I've added this information to the ticket.

Regards,

Hubert Mireault

avatar

Hello Hubert,

thank you very much for your feedback.

Yes, this soloution also would be helpful.

Best regards
Joerg