I received this on a form I submitted incorrectly today.

- Security is using HTTPS to encrypt traffic between my browser and the web server.
- Security would be to have the page automatically time out and redirect to a page without any of my personal information.
- Making me re-enter something I just typed because I forgot to fill out a form field is not added security, it's just inconvenient and annoying.
The same is true for sites that believe using fields with TYPE="PASSWORD" to mask the text somehow increases security. I have no empirical evidence, but I'm sure those forms are re-submitted significantly more than non-obscured counterparts. At the very least it makes users want to bite your face.


