Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #275727 > unrolled thread

a passwordless operating system

Started by🦓 <czyborra@gmail.com>
First post2024-12-15 09:00 +0100
Last post2024-12-16 09:20 +0100
Articles 20 on this page of 68 — 23 participants

Back to article view | Back to linux.debian.user


Contents

  a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
    Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
      Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
        Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
          Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
            Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
              Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
            Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
              Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
              Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
                  Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
                    Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
            Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
              Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
                Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
                  Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
                    Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
                      Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
                          Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
                              Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
                          Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
                            Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
                        Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                      Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
                          Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
                            Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
                            Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
                              Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
                                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
                                Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
                                  Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
                                  Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
                              Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
                  Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
                    Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
                      Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
                    Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                      Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
                      Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
                  Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
              Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
              Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
                Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
        Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
    Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
        Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
          Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
            Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
          Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
            Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
        Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100

Page 1 of 4  [1] 2 3 4  Next page →


#275727 — a passwordless operating system

From🦓 <czyborra@gmail.com>
Date2024-12-15 09:00 +0100
Subjecta passwordless operating system
Message-ID<JTRHH-h9O8-5@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

my mother is currently struggling to memorize all of my dead stepfather's
identities and passwords and that makes me wonder how would you like an
internet of hosts who store everything undeletably and barrierlessly
readably with no secrets whatsoever to humanity nor any other natural or
artificial or divine intelligence?   i know this sounds like a question for
debian-devel or debian-policy but i m dumping it onto debian-user as as of
now i m not subscribed to any other.

[toc] | [next] | [standalone]


#275734

Fromdebian-user@howorth.org.uk
Date2024-12-15 14:50 +0100
Message-ID<JTXap-hd9b-1@gated-at.bofh.it>
In reply to#275727
🦓 <czyborra@gmail.com> wrote:
> my mother is currently struggling to memorize all of my dead
> stepfather's identities and passwords and that makes me wonder how
> would you like an internet of hosts who store everything undeletably
> and barrierlessly readably with no secrets whatsoever to humanity nor
> any other natural or artificial or divine intelligence?   i know this
> sounds like a question for debian-devel or debian-policy but i m
> dumping it onto debian-user as as of now i m not subscribed to any
> other.

Why does your mother need to memorize all of your dead stepfather's
identities? Just let them die with him.

[toc] | [prev] | [next] | [standalone]


#275736

From🦓 <czyborra@gmail.com>
Date2024-12-15 15:30 +0100
Message-ID<JTXN7-hdCE-5@gated-at.bofh.it>
In reply to#275734

[Multipart message — attachments visible in raw view] — view raw

wouldnot be that like banks appropriating tons of gold deposited by
perished intelligentsia?

you die once when you die and twice when the last being remembering you dies

and i prefer computers to serve me rather than wreck my brain

<debian-user@howorth.org.uk> schrieb am So., 15. Dez. 2024, 14:49:

> 🦓 <czyborra@gmail.com> wrote:
> > my mother is currently struggling to memorize all of my dead
> > stepfather's identities and passwords and that makes me wonder how
> > would you like an internet of hosts who store everything undeletably
> > and barrierlessly readably with no secrets whatsoever to humanity nor
> > any other natural or artificial or divine intelligence?   i know this
> > sounds like a question for debian-devel or debian-policy but i m
> > dumping it onto debian-user as as of now i m not subscribed to any
> > other.
>
> Why does your mother need to memorize all of your dead stepfather's
> identities? Just let them die with him.
>
>

[toc] | [prev] | [next] | [standalone]


#275807

Fromsongbird <songbird@anthive.com>
Date2024-12-17 05:00 +0100
Message-ID<JUwUx-8vi-5@gated-at.bofh.it>
In reply to#275734
debian-user@howorth.org.uk wrote:
...
> Why does your mother need to memorize all of your dead stepfather's
> identities? Just let them die with him.

  perhaps because the accounts are jointly owned and it
is much easier to just continue using the credentials as
they exist instead of having to set everything up all
over again for no real gain.


  songbird

[toc] | [prev] | [next] | [standalone]


#275808

FromJohn Hasler <john@sugarbit.com>
Date2024-12-17 05:30 +0100
Message-ID<JUxnz-8U5-9@gated-at.bofh.it>
In reply to#275807
songbird writes:
> perhaps because the accounts are jointly owned and it is much easier
> to just continue using the credentials as they exist instead of having
> to set everything up all over again for no real gain.

Then follow Bruce Schneier's advice and*write them down*.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275809 — Writing passwords down [was: a passwordless operating system]

From<tomas@tuxteam.de>
Date2024-12-17 06:50 +0100
SubjectWriting passwords down [was: a passwordless operating system]
Message-ID<JUyCZ-9Eu-1@gated-at.bofh.it>
In reply to#275808

[Multipart message — attachments visible in raw view] — view raw

On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote:
> songbird writes:
> > perhaps because the accounts are jointly owned and it is much easier
> > to just continue using the credentials as they exist instead of having
> > to set everything up all over again for no real gain.
> 
> Then follow Bruce Schneier's advice and*write them down*.

Do you have a reference?

I ask because I'm in the middle of a discussion (and that was my advice,
too). Seeing what Schneier has to say on that would be very interesting.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275810 — Re: Writing passwords down [was: a passwordless operating system]

From"Loris Bennett" <loris.bennett@fu-berlin.de>
Date2024-12-17 08:30 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUAbL-aFI-1@gated-at.bofh.it>
In reply to#275809
<tomas@tuxteam.de> writes:

> On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote:
>> songbird writes:
>> > perhaps because the accounts are jointly owned and it is much easier
>> > to just continue using the credentials as they exist instead of having
>> > to set everything up all over again for no real gain.
>> 
>> Then follow Bruce Schneier's advice and*write them down*.
>
> Do you have a reference?
>
> I ask because I'm in the middle of a discussion (and that was my advice,
> too). Seeing what Schneier has to say on that would be very interesting.

I have a German copy of "Secrets & Lies" from 2001 in which Schneier
discusses writing passwords down on p. 138 (Chapter 9 "Identification
and Authentication, Section "Access Tokens").  He says that passwords
are no worse than other "simple tokens" (anything which can be stolen or
copied) but if you write them down, keeping them in your wallet can be
safer than sticking them with a post-it to you monitor.  His actual
advice is that you should only write half your password down and commit
the other half to memory.

Cheers,

Loris

-- 
This signature is currently under constuction.

[toc] | [prev] | [next] | [standalone]


#275811 — Re: Writing passwords down [was: a passwordless operating system]

From<tomas@tuxteam.de>
Date2024-12-17 08:50 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUAv7-aMC-3@gated-at.bofh.it>
In reply to#275810

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 17, 2024 at 08:07:52AM +0100, Loris Bennett wrote:
> <tomas@tuxteam.de> writes:
> 
> > On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote:
> >> songbird writes:
> >> > perhaps because the accounts are jointly owned and it is much easier
> >> > to just continue using the credentials as they exist instead of having
> >> > to set everything up all over again for no real gain.
> >> 
> >> Then follow Bruce Schneier's advice and*write them down*.
> >
> > Do you have a reference?
> >
> > I ask because I'm in the middle of a discussion (and that was my advice,
> > too). Seeing what Schneier has to say on that would be very interesting.
> 
> I have a German copy of "Secrets & Lies" from 2001 in which Schneier
> discusses writing passwords down on p. 138 (Chapter 9 "Identification
> and Authentication, Section "Access Tokens").  He says that passwords
> are no worse than other "simple tokens" (anything which can be stolen or
> copied) but if you write them down, keeping them in your wallet can be
> safer than sticking them with a post-it to you monitor.  His actual
> advice is that you should only write half your password down and commit
> the other half to memory.

Thanks :)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275836 — Re: Writing passwords down [was: a passwordless operating system]

FromMike Castle <dalgoda+debian@gmail.com>
Date2024-12-17 18:00 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUJ5n-g12-1@gated-at.bofh.it>
In reply to#275810
On Mon, Dec 16, 2024 at 11:27 PM Loris Bennett
<loris.bennett@fu-berlin.de> wrote:
>keeping them in your wallet can be
> safer than sticking them with a post-it to you monitor.

Just brought back memories.

When I was in college in the 1980s/1990s, in my OS class, the
instructor told of a time when he was walking down a hallway and could
read a coworker's password taped to his terminal.  (note: terminal,
not monitor, he was referring to a decade earlier)

His telling of the story was much more humorous that I can't reproduce
here in text.

Thanks for the smile.
mrc

[toc] | [prev] | [next] | [standalone]


#275826 — Re: Writing passwords down [was: a passwordless operating system]

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-17 15:30 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUGKe-eHG-11@gated-at.bofh.it>
In reply to#275809
On Tue, Dec 17, 2024 at 12:45 AM <tomas@tuxteam.de> wrote:
>
> On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote:
> > songbird writes:
> > > perhaps because the accounts are jointly owned and it is much easier
> > > to just continue using the credentials as they exist instead of having
> > > to set everything up all over again for no real gain.
> >
> > Then follow Bruce Schneier's advice and*write them down*.
>
> Do you have a reference?

You might also try Peter Gutmann's Engineering Security,
<https://www.cs.auckland.ac.nz/~pgut001/pubs/book.pdf>. From Chapter
7, Passwords, Section "Passwords on the Client" (p. 614):

    The most effective client-side password management technique that the
    typical computer user can employ is to write them down.

    No, you didn’t read that wrong. From what we’ve found out from the
    endless surveys and studies that have been done on this topic over the
    years (see the start of this chapter) and the analysis of how users
    currently deal with passwords (see the remainder of the chapter) this
    really is the most effective client-side password management technique
    for the typical user.

And from the Intro to the chapter (p. 564):

    This 1960s perspective of computing is the type of threat model that
    some of the password-security guidelines that are in use today were
    designed to counter! What’s worse is that even today, decades after
    these archaic threat models were employed as the basis for
    password-usage guidelines, we’re still fairly consistently giving
    users the wrong advice about password security such as “Passwords are
    like underwear, change them often” (solving no identifiable problem
    but creating several new ones, see “Password Lifetimes” on page
    574) and “Firewalls are useless if passwords are stuck to the monitor
    with a Post-it” [9] (phishers are pretty creative but the one thing
    they haven’t managed to do yet is reach out of the monitor to read
    your Post-it notes, see “Passwords on the Client” on page 614). As
    Bob Blakley puts it, “despite the fact that both attacks and losses
    have approximately doubled every year since 1992, we continue to rely
    on old models that are demonstrably ill-suited to the current reality
    and don’t inhibit the ongoing march of failure” [10].

Gutmann earned his PhD in security usability (SUX). And his book is
well cited with conference papers and security usability results.

> I ask because I'm in the middle of a discussion (and that was my advice,
> too). Seeing what Schneier has to say on that would be very interesting.

Jeff

[toc] | [prev] | [next] | [standalone]


#275828 — Re: Writing passwords down [was: a passwordless operating system]

FromLee <ler762@gmail.com>
Date2024-12-17 15:40 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUGTU-eL4-17@gated-at.bofh.it>
In reply to#275809
On Tue, Dec 17, 2024 at 12:45 AM tomas wrote:
>
> On Mon, Dec 16, 2024 at 10:22:43PM -0600, John Hasler wrote:
> > songbird writes:
> > > perhaps because the accounts are jointly owned and it is much easier
> > > to just continue using the credentials as they exist instead of having
> > > to set everything up all over again for no real gain.
> >
> > Then follow Bruce Schneier's advice and*write them down*.
>
> Do you have a reference?
>
> I ask because I'm in the middle of a discussion (and that was my advice,
> too). Seeing what Schneier has to say on that would be very interesting.

https://www.schneier.com/blog/archives/2005/06/write_down_your.html

Regards
Lee

[toc] | [prev] | [next] | [standalone]


#275829 — Re: libreoffice/openoffice system theme

From<tomas@tuxteam.de>
Date2024-12-17 16:00 +0100
SubjectRe: libreoffice/openoffice system theme
Message-ID<JUHdg-eRX-11@gated-at.bofh.it>
In reply to#275828

[Multipart message — attachments visible in raw view] — view raw

Thanks all!

Especially Gutmann's ref looks very interesting!

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275833 — Re: Writing passwords down [was: a passwordless operating system]

FromMichael Stone <mstone@debian.org>
Date2024-12-17 17:10 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUIiZ-fKY-3@gated-at.bofh.it>
In reply to#275809
On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote:
>Do you have a reference?
>
>I ask because I'm in the middle of a discussion (and that was my advice,
>too). Seeing what Schneier has to say on that would be very interesting.

All of this advice is overly simplistic. The right answer depends on 
understanding your threats and making a conscious decision what risks 
you want to mitigate and which you want to accept. If your threats 
include a coworker using your account to get a higher level of access 
than permitted, or to avoid/shift accountability, then putting your 
passwords on your monitor at work with a post-it is a tremendously 
stupid idea. If your threats include a person in your home (e.g., health 
aide, plumber's assistant, whatever) potentially accessing banking 
information, then putting your passwords on your monitor at home is a 
tremendously stupid idea. If your main threat is forgetting a password, 
and you don't have to worry at all about anyone else seeing your 
post-it, then putting your password on your monitor may be a very good 
idea. Putting your passwords in a notebook in a drawer may be a 
reasonable mitigation in some environments, but not others. Locking the 
drawer may or may not be an effective additional layer. People like to 
throw out bombs like "passwords should be written down" for shock value, 
but reality needs more effort and significantly more nuance. Schneier 
would, I think, agree with this as he already has nuances like "put it 
in your wallet". The problem of an elderly person with memory problems 
that potentially does/will have people in their home is particularly 
difficult as the wallet advice has minimal utility--there do exist 
people who take advantage of the elderly and steal their money, 
sometimes from their wallet and sometimes from their accounts, and if 
both are vulnerable it is not effective to secure one with the other. I 
don't think there is a good, general, simple answer to this without much 
more knowledge of the particulars of the situation than is probably 
appropriate for a mailing list.

[toc] | [prev] | [next] | [standalone]


#275837 — Re: Writing passwords down [was: a passwordless operating system]

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-17 18:30 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUJyp-gvF-3@gated-at.bofh.it>
In reply to#275833
On Tue, Dec 17, 2024 at 11:00 AM Michael Stone <mstone@debian.org> wrote:
>
> On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote:
> >Do you have a reference?
> >
> >I ask because I'm in the middle of a discussion (and that was my advice,
> >too). Seeing what Schneier has to say on that would be very interesting.
>
> All of this advice is overly simplistic.

I cited two paragraphs of a chapter that is 95 pages long. One was an
introductory paragraph for the chapter, the other was an introductory
paragraph for the section. There is a lot more to read.

> The right answer depends on
> understanding your threats and making a conscious decision what risks
> you want to mitigate and which you want to accept. [...]

I think you should read the chapter rather than commenting on two
introductory paragraphs.

Jeff

[toc] | [prev] | [next] | [standalone]


#275839 — Re: Writing passwords down [was: a passwordless operating system]

From"James H. H. Lampert" <jamesl@touchtonecorp.com>
Date2024-12-17 18:40 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUJI6-gzH-9@gated-at.bofh.it>
In reply to#275837
I make regular use of an OS that is completely passwordless.

It's called PC-DOS 2000.

(I might also add that I wish that my Meerkat desktop Linux box didn't 
make it so easy to sign off by mistake when I'd intended to power down.)

--
James H. H. Lampert

[toc] | [prev] | [next] | [standalone]


#275838 — Re: Writing passwords down [was: a passwordless operating system]

From<tomas@tuxteam.de>
Date2024-12-17 18:30 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUJyp-gvF-5@gated-at.bofh.it>
In reply to#275833

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote:
> On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote:
> > Do you have a reference?
> > 
> > I ask because I'm in the middle of a discussion (and that was my advice,
> > too). Seeing what Schneier has to say on that would be very interesting.
> 
> All of this advice is overly simplistic. The right answer depends on
> understanding your threats and making a conscious decision what risks you
> want to mitigate [...]

I know, I know. My introductory sentence is almost literally yours.

As times shift, threat models shift accordingly. Back then, when
computers and environments were more shared, post-its and shoulder
surfing were the main password leak threat, in-between it was the
(clear text) transport, these days it's probably phishing and
server-side breaches, which -- hopefully! -- yield a database of
salted hashes, in which case strong passwords are vital.

I'm still very interested in those references, not to follow them
blindly, but because they may contain insights I haven't had myself.
Especially in the case of Schneier, I'm doubly eager to listen.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275840 — Re: Writing passwords down [was: a passwordless operating system]

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-17 18:40 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUJI6-gzH-17@gated-at.bofh.it>
In reply to#275838
On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote:
>
> On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote:
> > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote:
> > > Do you have a reference?
> > >
> > > I ask because I'm in the middle of a discussion (and that was my advice,
> > > too). Seeing what Schneier has to say on that would be very interesting.
> >
> > All of this advice is overly simplistic. The right answer depends on
> > understanding your threats and making a conscious decision what risks you
> > want to mitigate [...]
>
> I know, I know. My introductory sentence is almost literally yours.
>
> As times shift, threat models shift accordingly. Back then, when
> computers and environments were more shared, post-its and shoulder
> surfing were the main password leak threat, in-between it was the
> (clear text) transport, these days it's probably phishing and
> server-side breaches, which -- hopefully! -- yield a database of
> salted hashes, in which case strong passwords are vital.
>
> I'm still very interested in those references, not to follow them
> blindly, but because they may contain insights I haven't had myself.
> Especially in the case of Schneier, I'm doubly eager to listen.

Schneier is security on training wheels. (Not to impune his work). It
is a good introduction, but it is written for a different audience.

If you really want to satisfy your security related hunger, then read
Gutmann's Engineering Security[1] or Ross Anderson's Security
Engineering.[2] I prefer Gutmann because it is so well cited. I often
pull the cited papers and read them for myself.

[1] <https://www.cs.auckland.ac.nz/~pgut001/pubs/book.pdf>
[2] <https://www.cl.cam.ac.uk/archive/rja14/book.html>

Jeff

[toc] | [prev] | [next] | [standalone]


#275843 — Re: Writing passwords down [was: a passwordless operating system]

Fromtomas@tuxteam.de
Date2024-12-17 19:30 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUKut-h5C-1@gated-at.bofh.it>
In reply to#275840

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 17, 2024 at 12:37:33PM -0500, Jeffrey Walton wrote:
> On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote:
> >
> > On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote:
> > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote:
> > > > Do you have a reference?
> > > >
> > > > I ask because I'm in the middle of a discussion (and that was my advice,
> > > > too). Seeing what Schneier has to say on that would be very interesting.
> > >
> > > All of this advice is overly simplistic. The right answer depends on
> > > understanding your threats and making a conscious decision what risks you
> > > want to mitigate [...]
> >
> > I know, I know. My introductory sentence is almost literally yours.
> >
> > As times shift, threat models shift accordingly. Back then, when
> > computers and environments were more shared, post-its and shoulder
> > surfing were the main password leak threat, in-between it was the
> > (clear text) transport, these days it's probably phishing and
> > server-side breaches, which -- hopefully! -- yield a database of
> > salted hashes, in which case strong passwords are vital.
> >
> > I'm still very interested in those references, not to follow them
> > blindly, but because they may contain insights I haven't had myself.
> > Especially in the case of Schneier, I'm doubly eager to listen.
> 
> Schneier is security on training wheels. (Not to impune his work). It
> is a good introduction, but it is written for a different audience.

Perfect for my purposes. I'm trying to get people to understand that
security is relative (to everything else around it, i.e. the famous
"threat model"). If they end up digesting Schneier's "process, not
product", I'm happy.

> If you really want to satisfy your security related hunger, then read
> Gutmann's Engineering Security[1] or Ross Anderson's Security
> Engineering.[2] I prefer Gutmann because it is so well cited. I often
> pull the cited papers and read them for myself.

Gutmann was mentioned in this thread. Anderson wrote in CACM's "Inside
Risks", right?

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275848 — Re: Writing passwords down [was: a passwordless operating system]

FromNicholas Geovanis <nickgeovanis@gmail.com>
Date2024-12-17 21:10 +0100
SubjectRe: Writing passwords down [was: a passwordless operating system]
Message-ID<JUM3f-i9u-7@gated-at.bofh.it>
In reply to#275843

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 17, 2024, 12:24 PM <tomas@tuxteam.de> wrote:

> On Tue, Dec 17, 2024 at 12:37:33PM -0500, Jeffrey Walton wrote:
> > On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote:
> > >
> > > On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote:
> > > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote:
> > > > > Do you have a reference?
> > > > >
> > > > > I ask because I'm in the middle of a discussion (and that was my
> advice,
> > > > > too). Seeing what Schneier has to say on that would be very
> interesting.
> > > >
> > > > All of this advice is overly simplistic. The right answer depends on
> > > > understanding your threats and making a conscious decision what
> risks you
> > > > want to mitigate [...]
> > >
> > > I know, I know. My introductory sentence is almost literally yours.
> > >
> > > As times shift, threat models shift accordingly. Back then, when
> > > computers and environments were more shared, post-its and shoulder
> > > surfing were the main password leak threat, in-between it was the
> > > (clear text) transport, these days it's probably phishing and
> > > server-side breaches, which -- hopefully! -- yield a database of
> > > salted hashes, in which case strong passwords are vital.
> > >
> > > I'm still very interested in those references, not to follow them
> > > blindly, but because they may contain insights I haven't had myself.
> > > Especially in the case of Schneier, I'm doubly eager to listen.
> >
> > Schneier is security on training wheels. (Not to impune his work). It
> > is a good introduction, but it is written for a different audience
>

His earlier book on cryptography was for a while the best source for people
who wrote code. I guess his BlowFish cipher has not stood up so well over
longer time. He started his career in the Chicago area at ATT.

Perfect for my purposes. I'm trying to get people to understand that
> security is relative (to everything else around it, i.e. the famous
> "threat model"). If they end up digesting Schneier's "process, not
> product", I'm happy.
>

Reading the US DoD Orange Book in 1990, we realized that a server secured
at the A level was essentially unusable for its purpose. At best a
single-user single-purpose machine. And that physical security is the
foundation of all other security, without it all else is meaningless. So
from a certain perspective, all of our efforts were futile :-)

The "Rainbow Books" have been freely available online for some years.

> If you really want to satisfy your security related hunger, then read
> > Gutmann's Engineering Security[1] or Ross Anderson's Security
> > Engineering.[2] I prefer Gutmann because it is so well cited. I often
> > pull the cited papers and read them for myself.
>

Papers by Bell and LaPadula on MAC and DAC are foundational, they used to
be freely available online. The original theoretical basis of the SElinux
model.

Gutmann was mentioned in this thread. Anderson wrote in CACM's "Inside
> Risks", right?
>
> Cheers
> --
> t
>

[toc] | [prev] | [next] | [standalone]


#275841 — Re: Writing passwords down

FromMichael Kjörling <c9bc136c6063@ewoof.net>
Date2024-12-17 18:50 +0100
SubjectRe: Writing passwords down
Message-ID<JUJRL-gD6-1@gated-at.bofh.it>
In reply to#275809
On 17 Dec 2024 06:45 +0100, from tomas@tuxteam.de:
>> Then follow Bruce Schneier's advice and*write them down*.
> 
> Do you have a reference?
> 
> I ask because I'm in the middle of a discussion (and that was my advice,
> too). Seeing what Schneier has to say on that would be very interesting.

Not Schneier, but consider also the UK National Cyber Security
Centre's position on password managers:
https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers

Under the heading "Should I use a password manager?" the opening is:
"Yes. Password managers are a good thing. They give you huge
advantages in a world where there's far too many passwords for anyone
to remember."

-- 
Michael Kjörling
🔗 https://michael.kjorling.se

[toc] | [prev] | [next] | [standalone]


Page 1 of 4  [1] 2 3 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web