Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #264400 > unrolled thread

debian forgot usr pw

Started bygene heskett <gheskett@shentel.net>
First post2023-12-08 02:10 +0100
Last post2023-12-08 22:50 +0100
Articles 13 — 10 participants

Back to article view | Back to linux.debian.user


Contents

  debian forgot usr pw gene heskett <gheskett@shentel.net> - 2023-12-08 02:10 +0100
    Re: debian forgot usr pw Greg Wooledge <greg@wooledge.org> - 2023-12-08 02:30 +0100
      Re: debian forgot usr pw gene heskett <gheskett@shentel.net> - 2023-12-08 02:50 +0100
        Re: debian forgot usr pw John Hasler <john@sugarbit.com> - 2023-12-08 06:10 +0100
          Re: debian forgot usr pw Pocket <pocket@columbus.rr.com> - 2023-12-08 14:00 +0100
            Re: debian forgot usr pw Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-12-09 07:40 +0100
              Re: debian forgot usr pw Pocket <pocket@columbus.rr.com> - 2023-12-09 15:10 +0100
        Re: debian forgot usr pw Max Nikulin <manikulin@gmail.com> - 2023-12-08 06:20 +0100
          Re: debian forgot usr pw yxcv@vienna.at - 2023-12-08 09:20 +0100
            Re: debian forgot usr pw debian-user@howorth.org.uk - 2023-12-08 12:30 +0100
            Re: debian forgot usr pw Anders Andersson <pipatron@gmail.com> - 2023-12-08 20:10 +0100
      Re: debian forgot usr pw John Hasler <john@sugarbit.com> - 2023-12-08 06:10 +0100
    Re: debian forgot usr pw David Christensen <dpchrist@holgerdanske.com> - 2023-12-08 22:50 +0100

#264400 — debian forgot usr pw

Fromgene heskett <gheskett@shentel.net>
Date2023-12-08 02:10 +0100
Subjectdebian forgot usr pw
Message-ID<HIxxn-c3Qq-1@gated-at.bofh.it>
I had a 3d slicer I was quitting to restart it and re-organish its 
caxhe, took my machine to a lockup showing half a workspace on one half 
the screen and half an adjacent workspace on the other half of the 
screen, no responce to the keyboard and no mouse. 28 days uptime which 
was better than most uptimes I have with bookworm. 2 weeks seems to be 
the norm.

TL;DR:

So I went to the front panel and pressed the reset button but when it 
came time to enter my pw, it just looped back to the login prompt.  So I 
did a full powerdown, enough times the psu finally went face down in the 
pool.  That was a good excuse to do an overdue D & C and some update 
installs while I was changing the supply, adding a 16 port sata-III 
controller and 8T worth of SSD's so I could use them to get amanda 
started again. Powered it up, bios found the new drives, but my pw was 
still rejected, it looped back to the login in 2 or 3 seconds.

I do not normally have a root pw set, just me, using sudo when I need to 
do root stuff. So at grub I hit e and changed quiet to single, 
eventually spotting in all the spew, something go flying by about the 
root account being locked, so "single" does not work.  And of course no 
scrollback to read that msgs detail.

Thats bug #1. Single for rescue demands a root pw. If no root, it should 
default to the name in the sudoers file. So I'm still locked out and 
this is the 3rd time debian 12 has done this to me. So I get out a 12.2 
net-install dvd and reboot to it, several times, but I was able to set a 
root pw so single worked but I still had to enter the new pw.

At this point I successfully changed /my/ passwd to something a bit 
longer expressing my frustration. So since all my other machine control 
machines have a full desktop with full net access, I went to one of the 
bananapi-m5's and sent firefox to google with the search string "linux 
login loops back to login", 2nd hit, on stackexchange said to delete 
anything that looked like ./XAuthority* and ditto ./xsession* something 
was contaminated, killing x or its newer wayland cousin.  Bingo! Next 
reboot was normal.

So that is bug #3. Deleting that stuff, possibly losing some setup 
details by then re-starting X (etc) with a clean slate is far more 
preferable to another format and reinstall just to delete the 
contaminated files, formatting everything and losing 25 years of my 
history like happened when those 2 new 2T seacrates died at about 6 
weeks runtime, within hours of each other a bit over a year ago.

Seems to me stuff like this ought to be fixable.

Many thanks for reading this far. Maybe someone with write perms on 
bugzilla can investigate?

Cheers, Gene Heskett.
-- 
"There are four boxes to be used in defense of liberty:
  soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
  - Louis D. Brandeis

[toc] | [next] | [standalone]


#264401

FromGreg Wooledge <greg@wooledge.org>
Date2023-12-08 02:30 +0100
Message-ID<HIxQJ-c3Wg-1@gated-at.bofh.it>
In reply to#264400
On Thu, Dec 07, 2023 at 08:06:52PM -0500, gene heskett wrote:
> Thats bug #1. Single for rescue demands a root pw.

This isn't a bug.  It's just how things *are*.

People who choose not to set a root password are simply setting themselves
up for this failure.  It *will* happen eventually.  I strongly recommend
setting a root password on your systems.  And you should either *use* it
once in a while, so you don't forget what it is, or else make it the same
as your regular account's password.  So you don't forget what it is.

If you *still* choose not to set a root password, then you will need to
know how to get around the issue you ran into.  You won't be able to use
single-user mode to rescue your system, so you'll need other ways.  There
are two straightforward alternatives: boot from external media (USB or CD
or DVD), or learn how to do the "init=/bin/bash" thing from your boot
loader, which includes bind-mounting /proc and /dev and so on.

[toc] | [prev] | [next] | [standalone]


#264402

Fromgene heskett <gheskett@shentel.net>
Date2023-12-08 02:50 +0100
Message-ID<HIya5-c42b-5@gated-at.bofh.it>
In reply to#264401
On 12/7/23 20:24, Greg Wooledge wrote:
> On Thu, Dec 07, 2023 at 08:06:52PM -0500, gene heskett wrote:
>> Thats bug #1. Single for rescue demands a root pw.
> 
> This isn't a bug.  It's just how things *are*.
> 
> People who choose not to set a root password are simply setting themselves
> up for this failure.  It *will* happen eventually.  I strongly recommend
> setting a root password on your systems.  And you should either *use* it
> once in a while, so you don't forget what it is, or else make it the same
> as your regular account's password.  So you don't forget what it is.
> 
> If you *still* choose not to set a root password, then you will need to
> know how to get around the issue you ran into.  You won't be able to use
> single-user mode to rescue your system, so you'll need other ways.  There
> are two straightforward alternatives: boot from external media (USB or CD
> or DVD), or learn how to do the "init=/bin/bash" thing from your boot
> loader, which includes bind-mounting /proc and /dev and so on.
> 
> .
I've now set a root pw, about 34 chars, so they'll be a couple eons 
guessing it AND (horrors) have written it down.
Cheers, Gene Heskett.
-- 
"There are four boxes to be used in defense of liberty:
  soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author, 1940)
If we desire respect for the law, we must first make the law respectable.
  - Louis D. Brandeis

[toc] | [prev] | [next] | [standalone]


#264411

FromJohn Hasler <john@sugarbit.com>
Date2023-12-08 06:10 +0100
Message-ID<HIBhD-c675-1@gated-at.bofh.it>
In reply to#264402
Gene writes:
> AND (horrors) have written it down.

That's the right thing to do.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#264417

FromPocket <pocket@columbus.rr.com>
Date2023-12-08 14:00 +0100
Message-ID<HIICt-caqJ-1@gated-at.bofh.it>
In reply to#264411
On 12/8/23 00:05, John Hasler wrote:
> Gene writes:
>> AND (horrors) have written it down.
> That's the right thing to do.

Well you could always use the universal password of password

I use for example i use the following

for the root account the password is root

for my user account of pocket the password is pocket

No one will every guess those password so I am completely protected

-- 

It's not easy to be me

[toc] | [prev] | [next] | [standalone]


#264465

FromTimothy M Butterworth <timothy.m.butterworth@gmail.com>
Date2023-12-09 07:40 +0100
Message-ID<HIZah-ckrP-1@gated-at.bofh.it>
In reply to#264417

[Multipart message — attachments visible in raw view] — view raw

On Fri, Dec 8, 2023 at 7:56 AM Pocket <pocket@columbus.rr.com> wrote:

>
> On 12/8/23 00:05, John Hasler wrote:
> > Gene writes:
> >> AND (horrors) have written it down.
> > That's the right thing to do.
>
> Well you could always use the universal password of password
>
> I use for example i use the following
>
> for the root account the password is root
>
> for my user account of pocket the password is pocket
>
> No one will every guess those password so I am completely protected
>

Thanks now I have your passwords and your IP address from the SMTP
header. 2001:41b8:202:deb:216:36ff:fe40:4002
Darn SSH is configured to use certificates. Your security is stronger than
you let on.

-- 
>
> It's not easy to be me
>
>

-- 
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
⠈⠳⣄⠀⠀

[toc] | [prev] | [next] | [standalone]


#264477

FromPocket <pocket@columbus.rr.com>
Date2023-12-09 15:10 +0100
Message-ID<HJ6bL-coO8-5@gated-at.bofh.it>
In reply to#264465

[Multipart message — attachments visible in raw view] — view raw

On 12/9/23 01:29, Timothy M Butterworth wrote:
>
>
> On Fri, Dec 8, 2023 at 7:56 AM Pocket <pocket@columbus.rr.com> wrote:
>
>
>     On 12/8/23 00:05, John Hasler wrote:
>     > Gene writes:
>     >> AND (horrors) have written it down.
>     > That's the right thing to do.
>
>     Well you could always use the universal password of password
>
>     I use for example i use the following
>
>     for the root account the password is root
>
>     for my user account of pocket the password is pocket
>
>     No one will every guess those password so I am completely protected
>
>
> Thanks now I have your passwords and your IP address from the SMTP 
> header. 2001:41b8:202:deb:216:36ff:fe40:4002 Darn SSH is configured to 
> use certificates. Your security is stronger than you let on.

LOL

whois 2001:41b8:202:deb:216:36ff:fe40:4002
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See https://apps.db.ripe.net/docs/HTML-Terms-And-Conditions

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to '2001:41b8:202::/48'

% Abuse contact for '2001:41b8:202::/48' is 'abuse@man-da.de'

inet6num:       2001:41b8:202::/48
netname:        DE-MANDA-DEBIAN-V6-01
descr:          Debian Darmstadt Network
country:        DE
admin-c:        DSAT1-RIPE
tech-c:         MAND2-RIPE
status:         ASSIGNED
mnt-by:         MANDA-MNT
created:        2015-07-09T09:24:37Z
last-modified:  2015-07-09T09:24:37Z
source:         RIPE # Filtered

role:           Debian System Administrators Team
address:        Software in the Public Interest, Inc
address:        Debian Project
address:        1732 1st Ave #20327
address:        New York, NY 10128-5177
address:        United States
org:            ORG-DA330-RIPE
remarks:        ********************************************
remarks:        **  in case of emergency find us on IRC   **
remarks:        **  irc://irc.debian.org/#debian-admin    **
remarks:        ********************************************
remarks:        **
remarks:        ********************************************
remarks:        **       Direct peering requests to       **
remarks:        ** peering@debian.org          **
remarks:        ********************************************

That doesn't belong to me



>
>     -- 
>
>     It's not easy to be me
>
>
>
> -- 
> ⢀⣴⠾⠻⢶⣦⠀
> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
> ⠈⠳⣄⠀⠀

-- 
It's not easy to be me

[toc] | [prev] | [next] | [standalone]


#264412

FromMax Nikulin <manikulin@gmail.com>
Date2023-12-08 06:20 +0100
Message-ID<HIBrj-c6aH-1@gated-at.bofh.it>
In reply to#264402
On 08/12/2023 08:49, gene heskett wrote:
> I've now set a root pw, about 34 chars, so they'll be a couple eons 
> guessing it AND (horrors) have written it down.

Consider pass phrases.

<https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases>
Deep Dive: EFF's New Wordlists for Random Passphrases
By Joseph Bonneau July 19, 2016

is declared to be an improvement of diceware.

kepassxc supports generation of pass phrases based on the EFF word list. 
A couple of memorable pass phrases (for different scopes) may protect 
other passwords stored in a password manager.

https://xkcd.com/936/ Password Strength
> To anyone who understands information theory and security and is in an
> infuriating argument with someone who does not (possibly involving mixed
> case), I sincerely apologize.

[toc] | [prev] | [next] | [standalone]


#264413

Fromyxcv@vienna.at
Date2023-12-08 09:20 +0100
Message-ID<HIEfv-c7Un-1@gated-at.bofh.it>
In reply to#264412
On Fri, 8 Dec 2023 12:17:35 +0700
  Max Nikulin <manikulin@gmail.com> wrote:
> 
> On 08/12/2023 08:49, gene heskett wrote:
>> I've now set a root pw, about 34 chars, so they'll be a couple eons 
>>guessing it AND (horrors) have written it down.
> 
> Consider pass phrases.
> 
> <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases>
> Deep Dive: EFF's New Wordlists for Random Passphrases
> By Joseph Bonneau July 19, 2016
> 
> is declared to be an improvement of diceware.

What is diceware?
Why trust EFF?

> kepassxc supports generation of pass phrases based on the EFF word 
>list. A couple of memorable pass phrases (for different scopes) may 
>protect other passwords stored in a password manager.
> 
> https://xkcd.com/936/ Password Strength

Or trusting "https://xkcd.com/936/ Password Strength" ?

[toc] | [prev] | [next] | [standalone]


#264414

Fromdebian-user@howorth.org.uk
Date2023-12-08 12:30 +0100
Message-ID<HIHdn-c9JZ-19@gated-at.bofh.it>
In reply to#264413
yxcv@vienna.at wrote:
> On Fri, 8 Dec 2023 12:17:35 +0700
>   Max Nikulin <manikulin@gmail.com> wrote:
> > 
> > On 08/12/2023 08:49, gene heskett wrote:  
> >> I've now set a root pw, about 34 chars, so they'll be a couple
> >> eons 
> >>guessing it AND (horrors) have written it down.  
> > 
> > Consider pass phrases.
> > 
> > <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases>
> > Deep Dive: EFF's New Wordlists for Random Passphrases
> > By Joseph Bonneau July 19, 2016
> > 
> > is declared to be an improvement of diceware.  
> 
> What is diceware?

Try asking google

> Why trust EFF?

See above

> > kepassxc supports generation of pass phrases based on the EFF word 
> >list. A couple of memorable pass phrases (for different scopes) may 
> >protect other passwords stored in a password manager.
> > 
> > https://xkcd.com/936/ Password Strength  
> 
> Or trusting "https://xkcd.com/936/ Password Strength" ?

Nobody's asking you to?

[toc] | [prev] | [next] | [standalone]


#264440

FromAnders Andersson <pipatron@gmail.com>
Date2023-12-08 20:10 +0100
Message-ID<HIOoy-ce4X-15@gated-at.bofh.it>
In reply to#264413
On Fri, Dec 8, 2023 at 9:10 AM <yxcv@vienna.at> wrote:
>
> On Fri, 8 Dec 2023 12:17:35 +0700
>   Max Nikulin <manikulin@gmail.com> wrote:
> >
> > On 08/12/2023 08:49, gene heskett wrote:
> >> I've now set a root pw, about 34 chars, so they'll be a couple eons
> >>guessing it AND (horrors) have written it down.
> >
> > Consider pass phrases.
> >
> > <https://www.eff.org/deeplinks/2016/07/new-wordlists-random-passphrases>
> > Deep Dive: EFF's New Wordlists for Random Passphrases
> > By Joseph Bonneau July 19, 2016
> >
> > is declared to be an improvement of diceware.
>
> What is diceware?
> Why trust EFF?
>
> > kepassxc supports generation of pass phrases based on the EFF word
> >list. A couple of memorable pass phrases (for different scopes) may
> >protect other passwords stored in a password manager.
> >
> > https://xkcd.com/936/ Password Strength
>
> Or trusting "https://xkcd.com/936/ Password Strength" ?

The xkcd link has all the information necessary to explain why it can
be trusted. It's like asking "Why trust that 1+1=2?" Maybe it's not,
but that's a philosophical question for snotty teenagers, not a
question for anyone doing anything useful.

[toc] | [prev] | [next] | [standalone]


#264410

FromJohn Hasler <john@sugarbit.com>
Date2023-12-08 06:10 +0100
Message-ID<HIBhD-c675-3@gated-at.bofh.it>
In reply to#264401
Greg writes:
> And you should either *use* it once in a while, so you don't forget
> what it is, or else make it the same as your regular account's
> password.

Write the damn thing down.  The world won't end.
-- 
John "Write all your passwords down. It isn't 1980 anymore." Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#264448

FromDavid Christensen <dpchrist@holgerdanske.com>
Date2023-12-08 22:50 +0100
Message-ID<HIQTn-cfqe-11@gated-at.bofh.it>
In reply to#264400
On 12/7/23 17:06, gene heskett wrote:
> I had a 3d slicer I was quitting to restart it and re-organish its 
> caxhe, took my machine to a lockup showing half a workspace on one half 
> the screen and half an adjacent workspace on the other half of the 
> screen, no responce to the keyboard and no mouse. 28 days uptime which 
> was better than most uptimes I have with bookworm. 2 weeks seems to be 
> the norm.
> 
> TL;DR:
> 
> So I went to the front panel and pressed the reset button but when it 
> came time to enter my pw, it just looped back to the login prompt.  So I 
> did a full powerdown, enough times the psu finally went face down in the 
> pool.  That was a good excuse to do an overdue D & C and some update 
> installs while I was changing the supply, adding a 16 port sata-III 
> controller and 8T worth of SSD's so I could use them to get amanda 
> started again. Powered it up, bios found the new drives, but my pw was 
> still rejected, it looped back to the login in 2 or 3 seconds.


A failing power supply can cause very strange behavior, including file 
corruption that will haunt you after replacing the power supply.


> I do not normally have a root pw set, just me, using sudo when I need to 
> do root stuff. So at grub I hit e and changed quiet to single, 
> eventually spotting in all the spew, something go flying by about the 
> root account being locked, so "single" does not work.  And of course no 
> scrollback to read that msgs detail.
>
> Thats bug #1. Single for rescue demands a root pw. If no root, it should 
> default to the name in the sudoers file. So I'm still locked out and 
> this is the 3rd time debian 12 has done this to me. So I get out a 12.2 
> net-install dvd and reboot to it, several times, but I was able to set a 
> root pw so single worked but I still had to enter the new pw.


While I always set a root password, I do agree that people should be 
able to run Debian without a root password and everything should still 
work.  Perhaps you should consider filing a bug report against grub (?).


> At this point I successfully changed /my/ passwd to something a bit 
> longer expressing my frustration. So since all my other machine control 
> machines have a full desktop with full net access, I went to one of the 
> bananapi-m5's and sent firefox to google with the search string "linux 
> login loops back to login", 2nd hit, on stackexchange said to delete 
> anything that looked like ./XAuthority* and ditto ./xsession* something 
> was contaminated, killing x or its newer wayland cousin.  Bingo! Next 
> reboot was normal.
> 
> So that is bug #3. Deleting that stuff, possibly losing some setup 
> details by then re-starting X (etc) with a clean slate is far more 
> preferable to another format and reinstall just to delete the 
> contaminated files, formatting everything and losing 25 years of my 
> history like happened when those 2 new 2T seacrates died at about 6 
> weeks runtime, within hours of each other a bit over a year ago.
> 
> Seems to me stuff like this ought to be fixable.
> 
> Many thanks for reading this far. Maybe someone with write perms on 
> bugzilla can investigate?
> 
> Cheers, Gene Heskett.


If I am understanding you correctly, $HOME/.Xauthority and/or 
$HOME/.xsession-errors became corrupt when the PSU failed, and the fix 
was to replace the PSU and delete those files?  About the only idea that 
comes to mind would be to put in a feature request against Xorg that 
Xorg implement some automatic failure recovery protocol that includes 
those files when Xorg fails to start the windowing environment.


That said, I have little faith in the "find the needle in the haystack" 
and "put Humpty Dumpty back together again" approach to fixing operating 
system instances.  Even when it "seems to work", I rarely have 
confidence in the results -- "what needles did I miss?"  My response to 
this situation is disaster preparedness --  I take images of my OS 
drives monthly, or as needed.  In fact, I had a UEFI Debian image go 
sideways last weekend during maintenance.  I spent ~15 minutes 
investigating/ trouble-shooting/ STFW/ RTFM/ etc., could not find the 
answer, spent ~15 minutes re-imaging, spent ~15 minutes updating, and 
was back in business with a known good OS instance in less than an hour 
without any outside help.


David

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web