It's not a downgrade to security for any password length:
- If it's so short that the knowledge of the length makes bruteforcing noticeably faster, the password is so short that the total length taken would be very short regardless.
- In all other cases, it removes such a small fraction of time needed (on the scale of removing one age-of-the-universe from a process that would otherwise take thousands of ages-of-the-universe) that it doesn't change any infeasible timescale to a feasible one.
So either the information isn't needed, or it won't help. So not a security decrease.
The correct change would be leave the default and put in the visudo file for easy uncommenting. The "developers opinion" is flat wrong.
# uncomment below to see *s when typing passwords # Defaults pwfeedback
All of the dev thinking on the matter is based on narrow use-cased "if you're on a a host where login to a login screen and people can see you... "
When users connect via ssh keys to production hosts and type sudo passwords, I do not one iota of potential security benefit lost.