Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #275727 > unrolled thread

a passwordless operating system

Started by🦓 <czyborra@gmail.com>
First post2024-12-15 09:00 +0100
Last post2024-12-16 09:20 +0100
Articles 20 on this page of 68 — 23 participants

Back to article view | Back to linux.debian.user


Contents

  a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
    Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
      Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
        Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
          Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
            Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
              Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
            Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
              Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
            Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
              Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
              Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
                Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
                  Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
                    Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
            Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
              Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
                Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
                  Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
                    Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
                      Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
                          Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
                              Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
                          Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
                            Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
                            Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
                        Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                      Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
                        Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
                          Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
                          Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
                            Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
                            Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
                              Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
                              Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
                                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
                                Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
                                  Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
                                  Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
                              Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
                  Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
                    Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
                      Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
                    Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
                      Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
                      Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
                  Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
                Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
              Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
              Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
                Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
        Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
    Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
      Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
        Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
          Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
            Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
          Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
            Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
        Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100

Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →


#275914 — Re: Writing passwords down

FromMax Nikulin <manikulin@gmail.com>
Date2024-12-20 04:30 +0100
SubjectRe: Writing passwords down
Message-ID<JVBS9-11bR-3@gated-at.bofh.it>
In reply to#275911
On 19/12/2024 15:56, Chris Green wrote:
> Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> different systems that I ssh to) long, unmemorable, passwords would be
> useless.

Generate a private key and add its public counterpart to 
~/.ssh/authorized_keys on remote machines. Locally running ssh-agent 
allows to authenticate on remote machines without typing the pass phrase 
for the private key for each connection. It is more secure than 
passwords against brute force attacks.

(You may have more than one private key and may configure ssh to use 
some key for specific set of servers.)

[toc] | [prev] | [next] | [standalone]


#275915 — Re: Writing passwords down

FromGeorge at Clug <Clug@goproject.info>
Date2024-12-20 05:40 +0100
SubjectRe: Writing passwords down
Message-ID<JVCXT-11Om-1@gated-at.bofh.it>
In reply to#275914

On Friday, 20-12-2024 at 14:22 Max Nikulin wrote:
> On 19/12/2024 15:56, Chris Green wrote:
> > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > different systems that I ssh to) long, unmemorable, passwords would be
> > useless.
> 
> Generate a private key and add its public counterpart to 
> ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent 
> allows to authenticate on remote machines without typing the pass phrase 
> for the private key for each connection. It is more secure than 
> passwords against brute force attacks.
> 
> (You may have more than one private key and may configure ssh to use 
> some key for specific set of servers.)
> 
> 

Another method for remote server management can be provided by Ansible and Ansible vault.

https://docs.ansible.com/ansible/latest/playbook_guide/playbooks_privilege_escalation.html

https://docs.ansible.com/ansible/latest/vault_guide/index.html


George.

[toc] | [prev] | [next] | [standalone]


#275916 — Re: Writing passwords down

From<tomas@tuxteam.de>
Date2024-12-20 05:40 +0100
SubjectRe: Writing passwords down
Message-ID<JVCXT-11Om-3@gated-at.bofh.it>
In reply to#275914

[Multipart message — attachments visible in raw view] — view raw

On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote:
> On 19/12/2024 15:56, Chris Green wrote:
> > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > different systems that I ssh to) long, unmemorable, passwords would be
> > useless.
> 
> Generate a private key and add its public counterpart to
> ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows
> to authenticate on remote machines without typing the pass phrase for the
> private key for each connection. It is more secure than passwords against
> brute force attacks.

Definitely. I was thinking specifically about passwords: what they are, how
they work. But it's clear that (asymmetric) crypto keys are worlds ahead
of passwords in terms of security, convenience (agent forwarding, anyone?)
LDAP integration and all of that. Whenever I have the choice, a SSH key it
is.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275917 — Re: Writing passwords down

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-20 06:10 +0100
SubjectRe: Writing passwords down
Message-ID<JVDqW-12dI-1@gated-at.bofh.it>
In reply to#275916
On Thu, Dec 19, 2024 at 11:36 PM <tomas@tuxteam.de> wrote:
>
> On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote:
> > On 19/12/2024 15:56, Chris Green wrote:
> > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > > different systems that I ssh to) long, unmemorable, passwords would be
> > > useless.
> >
> > Generate a private key and add its public counterpart to
> > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows
> > to authenticate on remote machines without typing the pass phrase for the
> > private key for each connection. It is more secure than passwords against
> > brute force attacks.
>
> Definitely. I was thinking specifically about passwords: what they are, how
> they work. But it's clear that (asymmetric) crypto keys are worlds ahead
> of passwords in terms of security, convenience (agent forwarding, anyone?)
> LDAP integration and all of that. Whenever I have the choice, a SSH key it
> is.

You can have public/private key crypto on the web, too. That's what
FIDO/FIDO2 devices provide, like YubiKeys. See
<https://docs.yubico.com/yesdk/users-manual/application-fido2/fido2-credentials.html>.

Prior to FIDO{2} protocols, there were common access cards (CAC) and
personal identity verification cards (PIV). They never really took off
outside the enterprise and government agencies like the DoD. I
personally like PIV cards because I've been using them off and on for
more than a decade. (Encrypted email in high security environments is
a different story. That still sucks).

The browsers never warmed up to client-side [TLS] certificates, so
public/private keys never really materialized on the web. There are
philosophical and technical reasons for it. But the browsers are the
ones that worked against it and hence, are responsible for it. (A lot
of people don't realize how much damage the CA/Browser cartel has done
to users of the web).

Jeff

[toc] | [prev] | [next] | [standalone]


#275921 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-20 10:50 +0100
SubjectRe: Writing passwords down
Message-ID<JVHNU-14U7-7@gated-at.bofh.it>
In reply to#275916
tomas@tuxteam.de wrote:
> [-- text/plain, encoding quoted-printable, charset: utf-8, 24 lines --]
> 
> On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote:
> > On 19/12/2024 15:56, Chris Green wrote:
> > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > > different systems that I ssh to) long, unmemorable, passwords would be
> > > useless.
> > 
> > Generate a private key and add its public counterpart to
> > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows
> > to authenticate on remote machines without typing the pass phrase for the
> > private key for each connection. It is more secure than passwords against
> > brute force attacks.
> 
> Definitely. I was thinking specifically about passwords: what they are, how
> they work. But it's clear that (asymmetric) crypto keys are worlds ahead
> of passwords in terms of security, convenience (agent forwarding, anyone?)
> LDAP integration and all of that. Whenever I have the choice, a SSH key it
> is.
> 
WHY????

It depends very much on the way your connection might get attacked.  A
key based ssh connection is (as you say) much more secure against
attacks directly on the remote server, but only if that remote server
has password login disabled. Your key based login is quite irrelevant
if there's actually a password that the intruder can guess.

At the local end using a passphrase protected ssh key is no better
than a password, both depend entirely on how easy the password or
passphrase can be guessed.  In fact my feeling is that password is
slightly better because if you are using ssh-agent as you may well
leave your system for short periods without logging off and then an
intruder will be able to log in to all those remote systems for which
ssh-agent has saved your key(s). (Physical security again!)  This last
is why I have my ssh-agent set to expire keys after a few minutes.

-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275922 — Re: Writing passwords down

FromGeorge at Clug <Clug@goproject.info>
Date2024-12-21 01:40 +0100
SubjectRe: Writing passwords down
Message-ID<JVVHb-1dvk-1@gated-at.bofh.it>
In reply to#275921

On Friday, 20-12-2024 at 20:21 Chris Green wrote:
> tomas@tuxteam.de wrote:
> > [-- text/plain, encoding quoted-printable, charset: utf-8, 24 lines --]
> > 
> > On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote:
> > > On 19/12/2024 15:56, Chris Green wrote:
> > > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > > > different systems that I ssh to) long, unmemorable, passwords would be
> > > > useless.
> > > 
> > > Generate a private key and add its public counterpart to
> > > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows
> > > to authenticate on remote machines without typing the pass phrase for the
> > > private key for each connection. It is more secure than passwords against
> > > brute force attacks.
> > 
> > Definitely. I was thinking specifically about passwords: what they are, how
> > they work. But it's clear that (asymmetric) crypto keys are worlds ahead
> > of passwords in terms of security, convenience (agent forwarding, anyone?)
> > LDAP integration and all of that. Whenever I have the choice, a SSH key it
> > is.
> > 
> WHY????
> 
> It depends very much on the way your connection might get attacked.  A
> key based ssh connection is (as you say) much more secure against
> attacks directly on the remote server, but only if that remote server
> has password login disabled. Your key based login is quite irrelevant
> if there's actually a password that the intruder can guess.
> 
> At the local end using a passphrase protected ssh key is no better
> than a password, both depend entirely on how easy the password or
> passphrase can be guessed.  In fact my feeling is that password is
> slightly better because if you are using ssh-agent as you may well
> leave your system for short periods without logging off and then an
> intruder will be able to log in to all those remote systems for which
> ssh-agent has saved your key(s). (Physical security again!)  This last
> is why I have my ssh-agent set to expire keys after a few minutes.

"nothing is secure"

Security is an interesting topic. 

People have attempted to make things secure for many years. 

When security is mentioned, I first think of wax seals on envelopes and physical locks and keys.  I wonder if the younger generations do?

1) When thinking about security, I like to remind myself that "nothing is secure", and all I can do is make it "more difficult for others to gain unapproved access". There is always a way to break through a security measure. Hence 'access attempt' mitigation, monitoring and logging are useful in security plans.

2) I also like to remind myself and others, "If I can access it via the Internet, then so can anyone in the world who has access to the Internet". Staring questions: Does it really needed to be connected to the Internet? Is remote access truly required?

3) Applying Security makes access less convenient.  The greater the security, usually the less convenient my access becomes. Hence weak passwords are less secure than complex, long passwords, ssh keys with passwords are less convenient than ssh keys without passwords, stored passwords are convenient but give others another option to gain access to your password. How much inconvenience are you able to accept? (it is a good question)

4) Understanding what methods can be used to gain access to your system, and how to bypass whatever security systems you choose to implement, is important when choosing a security method.

5) Finding what methods, level, etc of security you are happy to accept and what level of risk you are willing to accept is the first step in making a security plan. 

6) Keeping security patches up to date reduces ways people can inappropriate access your systems. But only reduces, never be lulled into thinking you are secure.

(please let me know if there is a simpler or more correct way to phrase this info, I like improving my knowledge. And there has to be more to security than the above).

Below is a link to an interesting list of suggestions. Somewhat inconvenient if one were to implement all suggestions.
https://tailscale.com/learn/ssh-security-best-practices-protecting-your-remote-access-infrastructure

George.


> 
> -- 
> Chris Green
> ·
> 
> 

[toc] | [prev] | [next] | [standalone]


#275924 — Re: Writing passwords down

FromMax Nikulin <manikulin@gmail.com>
Date2024-12-21 04:30 +0100
SubjectRe: Writing passwords down
Message-ID<JVYlH-1fbo-1@gated-at.bofh.it>
In reply to#275921
On 20/12/2024 16:21, Chris Green wrote:
> In fact my feeling is that password is
> slightly better because if you are using ssh-agent as you may well
> leave your system for short periods without logging off and then an
> intruder will be able to log in to all those remote systems for which
> ssh-agent has saved your key(s). (Physical security again!)  This last
> is why I have my ssh-agent set to expire keys after a few minutes.

I have not tried it, but my expectation is that it is possible to use 
key-based authentication without an agent. If it is true then a key 
usually has more entropy than a password (especially one easy to type), 
so no advantages of the latter.

 From my point of view, if an "intruder" may do something with a system 
during a short leave period then passwords should be considered as 
compromised and expiration period configured in ssh-agent does not matter.

Instead of expiration timeout I would consider removing keys from 
ssh-agent on screen locker activation (explicitly by a shortcut or due 
to some idle time). Perhaps e.g. keepassxc as a ssh-agent can do it out 
of the box. For openssh is should be scriptable as well.

I consider not adding to or removing a key from ssh-agent as a 
protection against my unintentional action.

Tomas, I am sorry that I failed to express it clear enough, believing 
that the quote is enough for the context. From my point of view, 
ssh-agent allows to reduce number of passwords that are in the active 
pool. A pass phrase to a key gives access to multiple hosts. On the 
other hand, I consider adding password to a password manager as a kind 
of writing them down. Logins for remote systems must be kept somewhere 
anyway, you just do not need to type them frequently.

Jeffrey, a hardware token is definitely is the next step in protection 
of ssh private keys and second factor for authentication. Of course, 
with some specific actions to not lost access in the case of token failure.

As to client certificates, I may easily confuse everything, but from 
comments in various discussions I had impression that at least in some 
Europe (maybe Baltic and/or Nordic) countries people have to use smart 
cards to access some services provided by their states. Some of them 
arrange authentication on their own servers using the same client 
certificates.

[toc] | [prev] | [next] | [standalone]


#275919 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-20 10:30 +0100
SubjectRe: Writing passwords down
Message-ID<JVHuy-14Nc-11@gated-at.bofh.it>
In reply to#275914
Max Nikulin <manikulin@gmail.com> wrote:
> On 19/12/2024 15:56, Chris Green wrote:
> > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > different systems that I ssh to) long, unmemorable, passwords would be
> > useless.
> 
> Generate a private key and add its public counterpart to 
> ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent 
> allows to authenticate on remote machines without typing the pass phrase 
> for the private key for each connection. It is more secure than 
> passwords against brute force attacks.
> 
Yes, but the passphrase for the private key then becomes your
"password that you have to remember".  The security of the actual
connection is better as an intruder has to guess the key but IMHO I
don't think that's the issue.  

I do in fact use ssh key based accessed for all my 'external' ssh
connections, as you say this is more secure against direct attacks on
the remote ssh server.  However I did say in my post above
"passwords/passphrases", I have to enter passphrases quite frequently
for these ssh connections (I have agent set so the passphrase expires
after a while), that's what I was talking about.


-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275861 — Re: Writing passwords down

FromMichael Kjörling <c9bc136c6063@ewoof.net>
Date2024-12-18 10:20 +0100
SubjectRe: Writing passwords down
Message-ID<JUYnL-sha-7@gated-at.bofh.it>
In reply to#275846
On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright):
> As you have to select the subset from some listboxes with a mouse,
> I would guess that the step is designed to defeat key-logging.

If someone has maliciously installed a keylogger, there's also likely
some kind of screen recording software, so this seems like security
theater.

-- 
Michael Kjörling
🔗 https://michael.kjorling.se

[toc] | [prev] | [next] | [standalone]


#275862 — Re: Writing passwords down

From<tomas@tuxteam.de>
Date2024-12-18 10:20 +0100
SubjectRe: Writing passwords down
Message-ID<JUYnL-sha-5@gated-at.bofh.it>
In reply to#275861

[Multipart message — attachments visible in raw view] — view raw

On Wed, Dec 18, 2024 at 09:10:23AM +0000, Michael Kjörling wrote:
> On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright):
> > As you have to select the subset from some listboxes with a mouse,
> > I would guess that the step is designed to defeat key-logging.
> 
> If someone has maliciously installed a keylogger, there's also likely
> some kind of screen recording software, so this seems like security
> theater.

Nowadays, with browsers, you can even get better than just "screen
recording". Think, e.g. Selenium, which can record "clickstreams"
on a browser with reference to the DOM objects (is usually used for
testing, but hey).

When doing "security analysis", I tend to lump "compromised client"
into one category.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275863 — Re: Writing passwords down

FromMichael Kjörling <c9bc136c6063@ewoof.net>
Date2024-12-18 10:30 +0100
SubjectRe: Writing passwords down
Message-ID<JUYxr-slQ-5@gated-at.bofh.it>
In reply to#275862
On 18 Dec 2024 10:15 +0100, from tomas@tuxteam.de:
> When doing "security analysis", I tend to lump "compromised client"
> into one category.

Case in point: Microsoft Windows Recall.

Plug that into your favorite web search engine if you aren't familiar
with it, and read some of the tech media coverage of it.

-- 
Michael Kjörling
🔗 https://michael.kjorling.se

[toc] | [prev] | [next] | [standalone]


#275882 — Re: Writing passwords down

FromChris Green <cl@isbd.net>
Date2024-12-18 18:20 +0100
SubjectRe: Writing passwords down
Message-ID<JV5Sh-y4C-1@gated-at.bofh.it>
In reply to#275861
Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
> On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright):
> > As you have to select the subset from some listboxes with a mouse,
> > I would guess that the step is designed to defeat key-logging.
> 
> If someone has maliciously installed a keylogger, there's also likely
> some kind of screen recording software, so this seems like security
> theater.
> 
Yes, I think things like key loggers or even simple 'shoulder surfing'
are the commonest ways of passwords being 'broken'.

-- 
Chris Green
·

[toc] | [prev] | [next] | [standalone]


#275885 — Re: Writing passwords down

From<tomas@tuxteam.de>
Date2024-12-18 19:00 +0100
SubjectRe: Writing passwords down
Message-ID<JV6uZ-yph-5@gated-at.bofh.it>
In reply to#275882

[Multipart message — attachments visible in raw view] — view raw

On Wed, Dec 18, 2024 at 04:55:59PM +0000, Chris Green wrote:
> Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
> > On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright):
> > > As you have to select the subset from some listboxes with a mouse,
> > > I would guess that the step is designed to defeat key-logging.
> > 
> > If someone has maliciously installed a keylogger, there's also likely
> > some kind of screen recording software, so this seems like security
> > theater.
> > 
> Yes, I think things like key loggers or even simple 'shoulder surfing'
> are the commonest ways of passwords being 'broken'.

That's 1980s-1990s. These days it's service negligence and phishing.

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#275891 — Re: Writing passwords down

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-18 19:20 +0100
SubjectRe: Writing passwords down
Message-ID<JV6Om-yM3-7@gated-at.bofh.it>
In reply to#275882
On Wed, Dec 18, 2024 at 12:10 PM Chris Green <cl@isbd.net> wrote:
>
> Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
> > On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright):
> > > As you have to select the subset from some listboxes with a mouse,
> > > I would guess that the step is designed to defeat key-logging.
> >
> > If someone has maliciously installed a keylogger, there's also likely
> > some kind of screen recording software, so this seems like security
> > theater.
> >
> Yes, I think things like key loggers or even simple 'shoulder surfing'
> are the commonest ways of passwords being 'broken'.

Shoulder surfing has never been a problem for most users. People sense
when someone is standing behind them and watching them. Homo sapiens
developed the defense millions of years ago at a time when we were
prey. (Gutmann discusses this in his book. I believe it is under the
chapter on User Psychology).

The useless password blanking/masking that hides typos is a solution
looking for a problem. And it creates problems where none previously
existed.

The one that really irks me is when entering a Wifi password on a big
screen tv. I would know if someone was looking in my bay window. And
if I am really paranoid I can close the curtains. There's no need to
blank/mask password characters.

And I am aware Edward Snowden puts a blanket over his head and laptop
when he unlocks his laptop. He is not a typical user. He is guarding
against hidden cameras monitoring keyboard keystrokes. Password
blanking/masking won't help him, either.

Jeff

[toc] | [prev] | [next] | [standalone]


#275945 — Re: Writing passwords down

FromFrank Jezzer <etphonehomefrance@gmail.com>
Date2024-12-22 17:30 +0100
SubjectRe: Writing passwords down
Message-ID<JWx05-1BFr-1@gated-at.bofh.it>
In reply to#275846
On 2024-12-17, John Hasler <john@sugarbit.com> wrote:
> Peter Hillier-Brook writes:
>> the nonsense about about not changing them ignores the obvious.
>
> What is that?
>
>> My bank performs security checks by requesting a sub-set of my
>> password.
>
> Sounds like a reason to find a new bank, in the meantime changing your
> password after every such request.  Surely they can't be hashing the
> passwords properly if that practice is of any use.

The problem is that your important information is not on your personal,
password-protected machine.

What good are your methods, as an Amuhrikan, if the IRS, your ISP, or the Social
Security Administration is cracked? Or maybe a credit agency, as has
already occurred. Nothing whatsoever.

C'est là où le bat blesse.

My French ISP was cracked, leaking my banking info. My medical insurance
entity (French tiers payant) was cracked, also leaking my personal
info. The cloud provider used by many French governmental agencies
suffered a fire in Strasbourg in which my personal information was lost.
All these things were beyond my control and had nothing to do with the
data or password-protection on my computer.

It's all useless babble here, if you are at all connected to the modern
world.

[toc] | [prev] | [next] | [standalone]


#275853 — Re: Writing passwords down

FromJeffrey Walton <noloader@gmail.com>
Date2024-12-17 23:30 +0100
SubjectRe: Writing passwords down
Message-ID<JUOeJ-jom-11@gated-at.bofh.it>
In reply to#275844
On Tue, Dec 17, 2024 at 5:22 PM Peter Hillier-Brook <phb@hbsys.plus.com> wrote:
>
> On 17/12/2024 17:44, Michael Kjörling wrote:
> > [...]
> > Under the heading "Should I use a password manager?" the opening is:
> > "Yes. Password managers are a good thing. They give you huge
> > advantages in a world where there's far too many passwords for anyone
> > to remember."
>
> I couldn't cope without PasswordSafe (thanks Mr. Schneier) and the
> nonsense  about about not changing them ignores the obvious. My bank
> performs security checks by requesting a sub-set of my password. It
> doesn't take a genius to work out that after several visits the complete
> password can be deduced.

Developer driven security is some of the worst security you will
encounter in life. Web developers always seem to find a new way to
dredge the bottom.

Jeff

[toc] | [prev] | [next] | [standalone]


#275845 — Re: Writing passwords down

FromJohn Hasler <john@sugarbit.com>
Date2024-12-17 20:30 +0100
SubjectRe: Writing passwords down
Message-ID<JULqx-hFf-5@gated-at.bofh.it>
In reply to#275841
 Michael Kjörling writes:
> Under the heading "Should I use a password manager?" the opening is:
> "Yes. Password managers are a good thing. They give you huge
> advantages in a world where there's far too many passwords for anyone
> to remember."

I use Firefox's built-in manager for "low threat" passwords such as that
for my Reddit account (I also write them down).  Most of my passwords
fall in this class.  Important passwords are recorded only in my "little
black book".

I also use a different user name for every Web account.

One reason for writing down all your passwords (even if only on a list
stored in your safe deposit box) is related to the item that started
this thread: not making things difficult for whoever has to deal with
your estate.
-- 
John Hasler 
john@sugarbit.com
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


#275849 — Re: Writing passwords down

Fromdebian-user@howorth.org.uk
Date2024-12-17 21:50 +0100
SubjectRe: Writing passwords down
Message-ID<JUMFX-imO-1@gated-at.bofh.it>
In reply to#275841
Michael Kjörling <c9bc136c6063@ewoof.net> wrote:
> On 17 Dec 2024 06:45 +0100, from tomas@tuxteam.de:
> >> Then follow Bruce Schneier's advice and*write them down*.  
> > 
> > Do you have a reference?
> > 
> > I ask because I'm in the middle of a discussion (and that was my
> > advice, too). Seeing what Schneier has to say on that would be very
> > interesting.  
> 
> Not Schneier, but consider also the UK National Cyber Security
> Centre's position on password managers:
> https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers

I tend to agree but I'll play Devil's Advocate here.

If I was NCSC would I prefer to break a few password managers or
millions of individual passwords?

> Under the heading "Should I use a password manager?" the opening is:
> "Yes. Password managers are a good thing. They give you huge
> advantages in a world where there's far too many passwords for anyone
> to remember."
> 

[toc] | [prev] | [next] | [standalone]


#275864 — Re: Writing passwords down

FromMichael Kjörling <c9bc136c6063@ewoof.net>
Date2024-12-18 10:30 +0100
SubjectRe: Writing passwords down
Message-ID<JUYxr-slQ-7@gated-at.bofh.it>
In reply to#275849
On 17 Dec 2024 20:44 +0000, from debian-user@howorth.org.uk:
>> https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers
> 
> I tend to agree but I'll play Devil's Advocate here.
> 
> If I was NCSC would I prefer to break a few password managers or
> millions of individual passwords?

Counterpoint: Absent a password manager, people in general are
_terrible_ at coming up with and remembering _good_ passwords.
Especially the hundreds (or more) of passwords you can easily get to
after being on the Internet for a while.

And yes, a little black book can definitely be a password manager
(assuming that you have some other way of generating good random
passwords). In fact, for some people that might even be better than a
digital solution, because a lot of people who have a poor grasp of
digital information security _do_ still have a decent grasp of
security surrounding physical possessions. They might not readily
grasp the implications of handing their unlocked phone over to a
stranger, but they probably do grasp the implications of handing their
home keys over to the same stranger.

-- 
Michael Kjörling
🔗 https://michael.kjorling.se

[toc] | [prev] | [next] | [standalone]


#275816

Fromdebian-user@howorth.org.uk
Date2024-12-17 12:10 +0100
Message-ID<JUDCG-cTN-5@gated-at.bofh.it>
In reply to#275807
songbird <songbird@anthive.com> wrote:
> debian-user@howorth.org.uk wrote:
> ...
> > Why does your mother need to memorize all of your dead stepfather's
> > identities? Just let them die with him.  
> 
>   perhaps because the accounts are jointly owned and it
> is much easier to just continue using the credentials as
> they exist instead of having to set everything up all
> over again for no real gain.

(1) I assumed the OP was talking about more than 'accounts' (meaning
financial accounts which I assume to be fairly few in number) but
rather was talking about forums, web sites etc etc.

(2) My wife and I have a joint account. My credentials and hers for the
account are completely separate and different.

(3) I now think the OP was trolling, so ...

[toc] | [prev] | [next] | [standalone]


Page 3 of 4 — ← Prev page 1 2 [3] 4  Next page →

Back to top | Article view | linux.debian.user


csiph-web