When a password must be entered by a user, password entry should not be displayed.
Additional Information:
Covert entry of passwords will prevent casual eavesdropping by onlookers. This represents an exception to the general recommendation that all entries should be displayed. Special characters (e.g., * or #) may be displayed with each keystroke rather than the actual characters being entered. Alternatively, blanks may be displayed accompanied by an audio cue (e.g., a click or beep) for keystroke feedback.