Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #275727 > unrolled thread
| Started by | 🦓 <czyborra@gmail.com> |
|---|---|
| First post | 2024-12-15 09:00 +0100 |
| Last post | 2024-12-16 09:20 +0100 |
| Articles | 20 on this page of 68 — 23 participants |
Back to article view | Back to linux.debian.user
a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100
Page 1 of 4 [1] 2 3 4 Next page →
| From | 🦓 <czyborra@gmail.com> |
|---|---|
| Date | 2024-12-15 09:00 +0100 |
| Subject | a passwordless operating system |
| Message-ID | <JTRHH-h9O8-5@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
my mother is currently struggling to memorize all of my dead stepfather's identities and passwords and that makes me wonder how would you like an internet of hosts who store everything undeletably and barrierlessly readably with no secrets whatsoever to humanity nor any other natural or artificial or divine intelligence? i know this sounds like a question for debian-devel or debian-policy but i m dumping it onto debian-user as as of now i m not subscribed to any other.
[toc] | [next] | [standalone]
| From | debian-user@howorth.org.uk |
|---|---|
| Date | 2024-12-15 14:50 +0100 |
| Message-ID | <JTXap-hd9b-1@gated-at.bofh.it> |
| In reply to | #275727 |
🦓 <czyborra@gmail.com> wrote: > my mother is currently struggling to memorize all of my dead > stepfather's identities and passwords and that makes me wonder how > would you like an internet of hosts who store everything undeletably > and barrierlessly readably with no secrets whatsoever to humanity nor > any other natural or artificial or divine intelligence? i know this > sounds like a question for debian-devel or debian-policy but i m > dumping it onto debian-user as as of now i m not subscribed to any > other. Why does your mother need to memorize all of your dead stepfather's identities? Just let them die with him.
[toc] | [prev] | [next] | [standalone]
| From | 🦓 <czyborra@gmail.com> |
|---|---|
| Date | 2024-12-15 15:30 +0100 |
| Message-ID | <JTXN7-hdCE-5@gated-at.bofh.it> |
| In reply to | #275734 |
[Multipart message — attachments visible in raw view] — view raw
wouldnot be that like banks appropriating tons of gold deposited by perished intelligentsia? you die once when you die and twice when the last being remembering you dies and i prefer computers to serve me rather than wreck my brain <debian-user@howorth.org.uk> schrieb am So., 15. Dez. 2024, 14:49: > 🦓 <czyborra@gmail.com> wrote: > > my mother is currently struggling to memorize all of my dead > > stepfather's identities and passwords and that makes me wonder how > > would you like an internet of hosts who store everything undeletably > > and barrierlessly readably with no secrets whatsoever to humanity nor > > any other natural or artificial or divine intelligence? i know this > > sounds like a question for debian-devel or debian-policy but i m > > dumping it onto debian-user as as of now i m not subscribed to any > > other. > > Why does your mother need to memorize all of your dead stepfather's > identities? Just let them die with him. > >
[toc] | [prev] | [next] | [standalone]
| From | songbird <songbird@anthive.com> |
|---|---|
| Date | 2024-12-17 05:00 +0100 |
| Message-ID | <JUwUx-8vi-5@gated-at.bofh.it> |
| In reply to | #275734 |
debian-user@howorth.org.uk wrote: ... > Why does your mother need to memorize all of your dead stepfather's > identities? Just let them die with him. perhaps because the accounts are jointly owned and it is much easier to just continue using the credentials as they exist instead of having to set everything up all over again for no real gain. songbird
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2024-12-17 05:30 +0100 |
| Message-ID | <JUxnz-8U5-9@gated-at.bofh.it> |
| In reply to | #275807 |
songbird writes: > perhaps because the accounts are jointly owned and it is much easier > to just continue using the credentials as they exist instead of having > to set everything up all over again for no real gain. Then follow Bruce Schneier's advice and*write them down*. -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-17 06:50 +0100 |
| Subject | Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUyCZ-9Eu-1@gated-at.bofh.it> |
| In reply to | #275808 |
[Multipart message — attachments visible in raw view] — view raw
On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote: > songbird writes: > > perhaps because the accounts are jointly owned and it is much easier > > to just continue using the credentials as they exist instead of having > > to set everything up all over again for no real gain. > > Then follow Bruce Schneier's advice and*write them down*. Do you have a reference? I ask because I'm in the middle of a discussion (and that was my advice, too). Seeing what Schneier has to say on that would be very interesting. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | "Loris Bennett" <loris.bennett@fu-berlin.de> |
|---|---|
| Date | 2024-12-17 08:30 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUAbL-aFI-1@gated-at.bofh.it> |
| In reply to | #275809 |
<tomas@tuxteam.de> writes: > On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote: >> songbird writes: >> > perhaps because the accounts are jointly owned and it is much easier >> > to just continue using the credentials as they exist instead of having >> > to set everything up all over again for no real gain. >> >> Then follow Bruce Schneier's advice and*write them down*. > > Do you have a reference? > > I ask because I'm in the middle of a discussion (and that was my advice, > too). Seeing what Schneier has to say on that would be very interesting. I have a German copy of "Secrets & Lies" from 2001 in which Schneier discusses writing passwords down on p. 138 (Chapter 9 "Identification and Authentication, Section "Access Tokens"). He says that passwords are no worse than other "simple tokens" (anything which can be stolen or copied) but if you write them down, keeping them in your wallet can be safer than sticking them with a post-it to you monitor. His actual advice is that you should only write half your password down and commit the other half to memory. Cheers, Loris -- This signature is currently under constuction.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-17 08:50 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUAv7-aMC-3@gated-at.bofh.it> |
| In reply to | #275810 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 17, 2024 at 08:07:52AM +0100, Loris Bennett wrote: > <tomas@tuxteam.de> writes: > > > On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote: > >> songbird writes: > >> > perhaps because the accounts are jointly owned and it is much easier > >> > to just continue using the credentials as they exist instead of having > >> > to set everything up all over again for no real gain. > >> > >> Then follow Bruce Schneier's advice and*write them down*. > > > > Do you have a reference? > > > > I ask because I'm in the middle of a discussion (and that was my advice, > > too). Seeing what Schneier has to say on that would be very interesting. > > I have a German copy of "Secrets & Lies" from 2001 in which Schneier > discusses writing passwords down on p. 138 (Chapter 9 "Identification > and Authentication, Section "Access Tokens"). He says that passwords > are no worse than other "simple tokens" (anything which can be stolen or > copied) but if you write them down, keeping them in your wallet can be > safer than sticking them with a post-it to you monitor. His actual > advice is that you should only write half your password down and commit > the other half to memory. Thanks :) Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Mike Castle <dalgoda+debian@gmail.com> |
|---|---|
| Date | 2024-12-17 18:00 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUJ5n-g12-1@gated-at.bofh.it> |
| In reply to | #275810 |
On Mon, Dec 16, 2024 at 11:27 PM Loris Bennett <loris.bennett@fu-berlin.de> wrote: >keeping them in your wallet can be > safer than sticking them with a post-it to you monitor. Just brought back memories. When I was in college in the 1980s/1990s, in my OS class, the instructor told of a time when he was walking down a hallway and could read a coworker's password taped to his terminal. (note: terminal, not monitor, he was referring to a decade earlier) His telling of the story was much more humorous that I can't reproduce here in text. Thanks for the smile. mrc
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-12-17 15:30 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUGKe-eHG-11@gated-at.bofh.it> |
| In reply to | #275809 |
On Tue, Dec 17, 2024 at 12:45 AM <tomas@tuxteam.de> wrote:
>
> On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote:
> > songbird writes:
> > > perhaps because the accounts are jointly owned and it is much easier
> > > to just continue using the credentials as they exist instead of having
> > > to set everything up all over again for no real gain.
> >
> > Then follow Bruce Schneier's advice and*write them down*.
>
> Do you have a reference?
You might also try Peter Gutmann's Engineering Security,
<https://www.cs.auckland.ac.nz/~pgut001/pubs/book.pdf>. From Chapter
7, Passwords, Section "Passwords on the Client" (p. 614):
The most effective client-side password management technique that the
typical computer user can employ is to write them down.
No, you didn’t read that wrong. From what we’ve found out from the
endless surveys and studies that have been done on this topic over the
years (see the start of this chapter) and the analysis of how users
currently deal with passwords (see the remainder of the chapter) this
really is the most effective client-side password management technique
for the typical user.
And from the Intro to the chapter (p. 564):
This 1960s perspective of computing is the type of threat model that
some of the password-security guidelines that are in use today were
designed to counter! What’s worse is that even today, decades after
these archaic threat models were employed as the basis for
password-usage guidelines, we’re still fairly consistently giving
users the wrong advice about password security such as “Passwords are
like underwear, change them often” (solving no identifiable problem
but creating several new ones, see “Password Lifetimes” on page
574) and “Firewalls are useless if passwords are stuck to the monitor
with a Post-it” [9] (phishers are pretty creative but the one thing
they haven’t managed to do yet is reach out of the monitor to read
your Post-it notes, see “Passwords on the Client” on page 614). As
Bob Blakley puts it, “despite the fact that both attacks and losses
have approximately doubled every year since 1992, we continue to rely
on old models that are demonstrably ill-suited to the current reality
and don’t inhibit the ongoing march of failure” [10].
Gutmann earned his PhD in security usability (SUX). And his book is
well cited with conference papers and security usability results.
> I ask because I'm in the middle of a discussion (and that was my advice,
> too). Seeing what Schneier has to say on that would be very interesting.
Jeff
[toc] | [prev] | [next] | [standalone]
| From | Lee <ler762@gmail.com> |
|---|---|
| Date | 2024-12-17 15:40 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUGTU-eL4-17@gated-at.bofh.it> |
| In reply to | #275809 |
On Tue, Dec 17, 2024 at 12:45 AM tomas wrote: > > On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote: > > songbird writes: > > > perhaps because the accounts are jointly owned and it is much easier > > > to just continue using the credentials as they exist instead of having > > > to set everything up all over again for no real gain. > > > > Then follow Bruce Schneier's advice and*write them down*. > > Do you have a reference? > > I ask because I'm in the middle of a discussion (and that was my advice, > too). Seeing what Schneier has to say on that would be very interesting. https://www.schneier.com/blog/archives/2005/06/write_down_your.html Regards Lee
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-17 16:00 +0100 |
| Subject | Re: libreoffice/openoffice system theme |
| Message-ID | <JUHdg-eRX-11@gated-at.bofh.it> |
| In reply to | #275828 |
[Multipart message — attachments visible in raw view] — view raw
Thanks all! Especially Gutmann's ref looks very interesting! Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Michael Stone <mstone@debian.org> |
|---|---|
| Date | 2024-12-17 17:10 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUIiZ-fKY-3@gated-at.bofh.it> |
| In reply to | #275809 |
On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: >Do you have a reference? > >I ask because I'm in the middle of a discussion (and that was my advice, >too). Seeing what Schneier has to say on that would be very interesting. All of this advice is overly simplistic. The right answer depends on understanding your threats and making a conscious decision what risks you want to mitigate and which you want to accept. If your threats include a coworker using your account to get a higher level of access than permitted, or to avoid/shift accountability, then putting your passwords on your monitor at work with a post-it is a tremendously stupid idea. If your threats include a person in your home (e.g., health aide, plumber's assistant, whatever) potentially accessing banking information, then putting your passwords on your monitor at home is a tremendously stupid idea. If your main threat is forgetting a password, and you don't have to worry at all about anyone else seeing your post-it, then putting your password on your monitor may be a very good idea. Putting your passwords in a notebook in a drawer may be a reasonable mitigation in some environments, but not others. Locking the drawer may or may not be an effective additional layer. People like to throw out bombs like "passwords should be written down" for shock value, but reality needs more effort and significantly more nuance. Schneier would, I think, agree with this as he already has nuances like "put it in your wallet". The problem of an elderly person with memory problems that potentially does/will have people in their home is particularly difficult as the wallet advice has minimal utility--there do exist people who take advantage of the elderly and steal their money, sometimes from their wallet and sometimes from their accounts, and if both are vulnerable it is not effective to secure one with the other. I don't think there is a good, general, simple answer to this without much more knowledge of the particulars of the situation than is probably appropriate for a mailing list.
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-12-17 18:30 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUJyp-gvF-3@gated-at.bofh.it> |
| In reply to | #275833 |
On Tue, Dec 17, 2024 at 11:00 AM Michael Stone <mstone@debian.org> wrote: > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: > >Do you have a reference? > > > >I ask because I'm in the middle of a discussion (and that was my advice, > >too). Seeing what Schneier has to say on that would be very interesting. > > All of this advice is overly simplistic. I cited two paragraphs of a chapter that is 95 pages long. One was an introductory paragraph for the chapter, the other was an introductory paragraph for the section. There is a lot more to read. > The right answer depends on > understanding your threats and making a conscious decision what risks > you want to mitigate and which you want to accept. [...] I think you should read the chapter rather than commenting on two introductory paragraphs. Jeff
[toc] | [prev] | [next] | [standalone]
| From | "James H. H. Lampert" <jamesl@touchtonecorp.com> |
|---|---|
| Date | 2024-12-17 18:40 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUJI6-gzH-9@gated-at.bofh.it> |
| In reply to | #275837 |
I make regular use of an OS that is completely passwordless. It's called PC-DOS 2000. (I might also add that I wish that my Meerkat desktop Linux box didn't make it so easy to sign off by mistake when I'd intended to power down.) -- James H. H. Lampert
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-17 18:30 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUJyp-gvF-5@gated-at.bofh.it> |
| In reply to | #275833 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote: > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: > > Do you have a reference? > > > > I ask because I'm in the middle of a discussion (and that was my advice, > > too). Seeing what Schneier has to say on that would be very interesting. > > All of this advice is overly simplistic. The right answer depends on > understanding your threats and making a conscious decision what risks you > want to mitigate [...] I know, I know. My introductory sentence is almost literally yours. As times shift, threat models shift accordingly. Back then, when computers and environments were more shared, post-its and shoulder surfing were the main password leak threat, in-between it was the (clear text) transport, these days it's probably phishing and server-side breaches, which -- hopefully! -- yield a database of salted hashes, in which case strong passwords are vital. I'm still very interested in those references, not to follow them blindly, but because they may contain insights I haven't had myself. Especially in the case of Schneier, I'm doubly eager to listen. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-12-17 18:40 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUJI6-gzH-17@gated-at.bofh.it> |
| In reply to | #275838 |
On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote: > > On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote: > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: > > > Do you have a reference? > > > > > > I ask because I'm in the middle of a discussion (and that was my advice, > > > too). Seeing what Schneier has to say on that would be very interesting. > > > > All of this advice is overly simplistic. The right answer depends on > > understanding your threats and making a conscious decision what risks you > > want to mitigate [...] > > I know, I know. My introductory sentence is almost literally yours. > > As times shift, threat models shift accordingly. Back then, when > computers and environments were more shared, post-its and shoulder > surfing were the main password leak threat, in-between it was the > (clear text) transport, these days it's probably phishing and > server-side breaches, which -- hopefully! -- yield a database of > salted hashes, in which case strong passwords are vital. > > I'm still very interested in those references, not to follow them > blindly, but because they may contain insights I haven't had myself. > Especially in the case of Schneier, I'm doubly eager to listen. Schneier is security on training wheels. (Not to impune his work). It is a good introduction, but it is written for a different audience. If you really want to satisfy your security related hunger, then read Gutmann's Engineering Security[1] or Ross Anderson's Security Engineering.[2] I prefer Gutmann because it is so well cited. I often pull the cited papers and read them for myself. [1] <https://www.cs.auckland.ac.nz/~pgut001/pubs/book.pdf> [2] <https://www.cl.cam.ac.uk/archive/rja14/book.html> Jeff
[toc] | [prev] | [next] | [standalone]
| From | tomas@tuxteam.de |
|---|---|
| Date | 2024-12-17 19:30 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUKut-h5C-1@gated-at.bofh.it> |
| In reply to | #275840 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 17, 2024 at 12:37:33PM -0500, Jeffrey Walton wrote: > On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote: > > > > On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote: > > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: > > > > Do you have a reference? > > > > > > > > I ask because I'm in the middle of a discussion (and that was my advice, > > > > too). Seeing what Schneier has to say on that would be very interesting. > > > > > > All of this advice is overly simplistic. The right answer depends on > > > understanding your threats and making a conscious decision what risks you > > > want to mitigate [...] > > > > I know, I know. My introductory sentence is almost literally yours. > > > > As times shift, threat models shift accordingly. Back then, when > > computers and environments were more shared, post-its and shoulder > > surfing were the main password leak threat, in-between it was the > > (clear text) transport, these days it's probably phishing and > > server-side breaches, which -- hopefully! -- yield a database of > > salted hashes, in which case strong passwords are vital. > > > > I'm still very interested in those references, not to follow them > > blindly, but because they may contain insights I haven't had myself. > > Especially in the case of Schneier, I'm doubly eager to listen. > > Schneier is security on training wheels. (Not to impune his work). It > is a good introduction, but it is written for a different audience. Perfect for my purposes. I'm trying to get people to understand that security is relative (to everything else around it, i.e. the famous "threat model"). If they end up digesting Schneier's "process, not product", I'm happy. > If you really want to satisfy your security related hunger, then read > Gutmann's Engineering Security[1] or Ross Anderson's Security > Engineering.[2] I prefer Gutmann because it is so well cited. I often > pull the cited papers and read them for myself. Gutmann was mentioned in this thread. Anderson wrote in CACM's "Inside Risks", right? Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Date | 2024-12-17 21:10 +0100 |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Message-ID | <JUM3f-i9u-7@gated-at.bofh.it> |
| In reply to | #275843 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 17, 2024, 12:24 PM <tomas@tuxteam.de> wrote: > On Tue, Dec 17, 2024 at 12:37:33PM -0500, Jeffrey Walton wrote: > > On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote: > > > > > > On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote: > > > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: > > > > > Do you have a reference? > > > > > > > > > > I ask because I'm in the middle of a discussion (and that was my > advice, > > > > > too). Seeing what Schneier has to say on that would be very > interesting. > > > > > > > > All of this advice is overly simplistic. The right answer depends on > > > > understanding your threats and making a conscious decision what > risks you > > > > want to mitigate [...] > > > > > > I know, I know. My introductory sentence is almost literally yours. > > > > > > As times shift, threat models shift accordingly. Back then, when > > > computers and environments were more shared, post-its and shoulder > > > surfing were the main password leak threat, in-between it was the > > > (clear text) transport, these days it's probably phishing and > > > server-side breaches, which -- hopefully! -- yield a database of > > > salted hashes, in which case strong passwords are vital. > > > > > > I'm still very interested in those references, not to follow them > > > blindly, but because they may contain insights I haven't had myself. > > > Especially in the case of Schneier, I'm doubly eager to listen. > > > > Schneier is security on training wheels. (Not to impune his work). It > > is a good introduction, but it is written for a different audience > His earlier book on cryptography was for a while the best source for people who wrote code. I guess his BlowFish cipher has not stood up so well over longer time. He started his career in the Chicago area at ATT. Perfect for my purposes. I'm trying to get people to understand that > security is relative (to everything else around it, i.e. the famous > "threat model"). If they end up digesting Schneier's "process, not > product", I'm happy. > Reading the US DoD Orange Book in 1990, we realized that a server secured at the A level was essentially unusable for its purpose. At best a single-user single-purpose machine. And that physical security is the foundation of all other security, without it all else is meaningless. So from a certain perspective, all of our efforts were futile :-) The "Rainbow Books" have been freely available online for some years. > If you really want to satisfy your security related hunger, then read > > Gutmann's Engineering Security[1] or Ross Anderson's Security > > Engineering.[2] I prefer Gutmann because it is so well cited. I often > > pull the cited papers and read them for myself. > Papers by Bell and LaPadula on MAC and DAC are foundational, they used to be freely available online. The original theoretical basis of the SElinux model. Gutmann was mentioned in this thread. Anderson wrote in CACM's "Inside > Risks", right? > > Cheers > -- > t >
[toc] | [prev] | [next] | [standalone]
| From | Michael Kjörling <c9bc136c6063@ewoof.net> |
|---|---|
| Date | 2024-12-17 18:50 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUJRL-gD6-1@gated-at.bofh.it> |
| In reply to | #275809 |
On 17 Dec 2024 06:45 +0100, from tomas@tuxteam.de: >> Then follow Bruce Schneier's advice and*write them down*. > > Do you have a reference? > > I ask because I'm in the middle of a discussion (and that was my advice, > too). Seeing what Schneier has to say on that would be very interesting. Not Schneier, but consider also the UK National Cyber Security Centre's position on password managers: https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers Under the heading "Should I use a password manager?" the opening is: "Yes. Password managers are a good thing. They give you huge advantages in a world where there's far too many passwords for anyone to remember." -- Michael Kjörling 🔗 https://michael.kjorling.se
[toc] | [prev] | [next] | [standalone]
Page 1 of 4 [1] 2 3 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web