Yep, that's right.
For a multi usage environment an admin control function is desireable anyway, to be able to set what exactlly allowed to whom.
The visible password function as such will not increase hacking vulnerability. It does increase user friendliness though.
|