Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #275727 > unrolled thread
| Started by | 🦓 <czyborra@gmail.com> |
|---|---|
| First post | 2024-12-15 09:00 +0100 |
| Last post | 2024-12-16 09:20 +0100 |
| Articles | 20 on this page of 68 — 23 participants |
Back to article view | Back to linux.debian.user
a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2024-12-20 04:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVBS9-11bR-3@gated-at.bofh.it> |
| In reply to | #275911 |
On 19/12/2024 15:56, Chris Green wrote: > Horses for courses, I enter login passwords/passphrases quite frequently (lots of > different systems that I ssh to) long, unmemorable, passwords would be > useless. Generate a private key and add its public counterpart to ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows to authenticate on remote machines without typing the pass phrase for the private key for each connection. It is more secure than passwords against brute force attacks. (You may have more than one private key and may configure ssh to use some key for specific set of servers.)
[toc] | [prev] | [next] | [standalone]
| From | George at Clug <Clug@goproject.info> |
|---|---|
| Date | 2024-12-20 05:40 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVCXT-11Om-1@gated-at.bofh.it> |
| In reply to | #275914 |
On Friday, 20-12-2024 at 14:22 Max Nikulin wrote: > On 19/12/2024 15:56, Chris Green wrote: > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of > > different systems that I ssh to) long, unmemorable, passwords would be > > useless. > > Generate a private key and add its public counterpart to > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent > allows to authenticate on remote machines without typing the pass phrase > for the private key for each connection. It is more secure than > passwords against brute force attacks. > > (You may have more than one private key and may configure ssh to use > some key for specific set of servers.) > > Another method for remote server management can be provided by Ansible and Ansible vault. https://docs.ansible.com/ansible/latest/playbook_guide/playbooks_privilege_escalation.html https://docs.ansible.com/ansible/latest/vault_guide/index.html George.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-20 05:40 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVCXT-11Om-3@gated-at.bofh.it> |
| In reply to | #275914 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote: > On 19/12/2024 15:56, Chris Green wrote: > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of > > different systems that I ssh to) long, unmemorable, passwords would be > > useless. > > Generate a private key and add its public counterpart to > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows > to authenticate on remote machines without typing the pass phrase for the > private key for each connection. It is more secure than passwords against > brute force attacks. Definitely. I was thinking specifically about passwords: what they are, how they work. But it's clear that (asymmetric) crypto keys are worlds ahead of passwords in terms of security, convenience (agent forwarding, anyone?) LDAP integration and all of that. Whenever I have the choice, a SSH key it is. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-12-20 06:10 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVDqW-12dI-1@gated-at.bofh.it> |
| In reply to | #275916 |
On Thu, Dec 19, 2024 at 11:36 PM <tomas@tuxteam.de> wrote:
>
> On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote:
> > On 19/12/2024 15:56, Chris Green wrote:
> > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of
> > > different systems that I ssh to) long, unmemorable, passwords would be
> > > useless.
> >
> > Generate a private key and add its public counterpart to
> > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows
> > to authenticate on remote machines without typing the pass phrase for the
> > private key for each connection. It is more secure than passwords against
> > brute force attacks.
>
> Definitely. I was thinking specifically about passwords: what they are, how
> they work. But it's clear that (asymmetric) crypto keys are worlds ahead
> of passwords in terms of security, convenience (agent forwarding, anyone?)
> LDAP integration and all of that. Whenever I have the choice, a SSH key it
> is.
You can have public/private key crypto on the web, too. That's what
FIDO/FIDO2 devices provide, like YubiKeys. See
<https://docs.yubico.com/yesdk/users-manual/application-fido2/fido2-credentials.html>.
Prior to FIDO{2} protocols, there were common access cards (CAC) and
personal identity verification cards (PIV). They never really took off
outside the enterprise and government agencies like the DoD. I
personally like PIV cards because I've been using them off and on for
more than a decade. (Encrypted email in high security environments is
a different story. That still sucks).
The browsers never warmed up to client-side [TLS] certificates, so
public/private keys never really materialized on the web. There are
philosophical and technical reasons for it. But the browsers are the
ones that worked against it and hence, are responsible for it. (A lot
of people don't realize how much damage the CA/Browser cartel has done
to users of the web).
Jeff
[toc] | [prev] | [next] | [standalone]
| From | Chris Green <cl@isbd.net> |
|---|---|
| Date | 2024-12-20 10:50 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVHNU-14U7-7@gated-at.bofh.it> |
| In reply to | #275916 |
tomas@tuxteam.de wrote: > [-- text/plain, encoding quoted-printable, charset: utf-8, 24 lines --] > > On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote: > > On 19/12/2024 15:56, Chris Green wrote: > > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of > > > different systems that I ssh to) long, unmemorable, passwords would be > > > useless. > > > > Generate a private key and add its public counterpart to > > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows > > to authenticate on remote machines without typing the pass phrase for the > > private key for each connection. It is more secure than passwords against > > brute force attacks. > > Definitely. I was thinking specifically about passwords: what they are, how > they work. But it's clear that (asymmetric) crypto keys are worlds ahead > of passwords in terms of security, convenience (agent forwarding, anyone?) > LDAP integration and all of that. Whenever I have the choice, a SSH key it > is. > WHY???? It depends very much on the way your connection might get attacked. A key based ssh connection is (as you say) much more secure against attacks directly on the remote server, but only if that remote server has password login disabled. Your key based login is quite irrelevant if there's actually a password that the intruder can guess. At the local end using a passphrase protected ssh key is no better than a password, both depend entirely on how easy the password or passphrase can be guessed. In fact my feeling is that password is slightly better because if you are using ssh-agent as you may well leave your system for short periods without logging off and then an intruder will be able to log in to all those remote systems for which ssh-agent has saved your key(s). (Physical security again!) This last is why I have my ssh-agent set to expire keys after a few minutes. -- Chris Green ·
[toc] | [prev] | [next] | [standalone]
| From | George at Clug <Clug@goproject.info> |
|---|---|
| Date | 2024-12-21 01:40 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVVHb-1dvk-1@gated-at.bofh.it> |
| In reply to | #275921 |
On Friday, 20-12-2024 at 20:21 Chris Green wrote: > tomas@tuxteam.de wrote: > > [-- text/plain, encoding quoted-printable, charset: utf-8, 24 lines --] > > > > On Fri, Dec 20, 2024 at 10:22:29AM +0700, Max Nikulin wrote: > > > On 19/12/2024 15:56, Chris Green wrote: > > > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of > > > > different systems that I ssh to) long, unmemorable, passwords would be > > > > useless. > > > > > > Generate a private key and add its public counterpart to > > > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent allows > > > to authenticate on remote machines without typing the pass phrase for the > > > private key for each connection. It is more secure than passwords against > > > brute force attacks. > > > > Definitely. I was thinking specifically about passwords: what they are, how > > they work. But it's clear that (asymmetric) crypto keys are worlds ahead > > of passwords in terms of security, convenience (agent forwarding, anyone?) > > LDAP integration and all of that. Whenever I have the choice, a SSH key it > > is. > > > WHY???? > > It depends very much on the way your connection might get attacked. A > key based ssh connection is (as you say) much more secure against > attacks directly on the remote server, but only if that remote server > has password login disabled. Your key based login is quite irrelevant > if there's actually a password that the intruder can guess. > > At the local end using a passphrase protected ssh key is no better > than a password, both depend entirely on how easy the password or > passphrase can be guessed. In fact my feeling is that password is > slightly better because if you are using ssh-agent as you may well > leave your system for short periods without logging off and then an > intruder will be able to log in to all those remote systems for which > ssh-agent has saved your key(s). (Physical security again!) This last > is why I have my ssh-agent set to expire keys after a few minutes. "nothing is secure" Security is an interesting topic. People have attempted to make things secure for many years. When security is mentioned, I first think of wax seals on envelopes and physical locks and keys. I wonder if the younger generations do? 1) When thinking about security, I like to remind myself that "nothing is secure", and all I can do is make it "more difficult for others to gain unapproved access". There is always a way to break through a security measure. Hence 'access attempt' mitigation, monitoring and logging are useful in security plans. 2) I also like to remind myself and others, "If I can access it via the Internet, then so can anyone in the world who has access to the Internet". Staring questions: Does it really needed to be connected to the Internet? Is remote access truly required? 3) Applying Security makes access less convenient. The greater the security, usually the less convenient my access becomes. Hence weak passwords are less secure than complex, long passwords, ssh keys with passwords are less convenient than ssh keys without passwords, stored passwords are convenient but give others another option to gain access to your password. How much inconvenience are you able to accept? (it is a good question) 4) Understanding what methods can be used to gain access to your system, and how to bypass whatever security systems you choose to implement, is important when choosing a security method. 5) Finding what methods, level, etc of security you are happy to accept and what level of risk you are willing to accept is the first step in making a security plan. 6) Keeping security patches up to date reduces ways people can inappropriate access your systems. But only reduces, never be lulled into thinking you are secure. (please let me know if there is a simpler or more correct way to phrase this info, I like improving my knowledge. And there has to be more to security than the above). Below is a link to an interesting list of suggestions. Somewhat inconvenient if one were to implement all suggestions. https://tailscale.com/learn/ssh-security-best-practices-protecting-your-remote-access-infrastructure George. > > -- > Chris Green > · > >
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2024-12-21 04:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVYlH-1fbo-1@gated-at.bofh.it> |
| In reply to | #275921 |
On 20/12/2024 16:21, Chris Green wrote: > In fact my feeling is that password is > slightly better because if you are using ssh-agent as you may well > leave your system for short periods without logging off and then an > intruder will be able to log in to all those remote systems for which > ssh-agent has saved your key(s). (Physical security again!) This last > is why I have my ssh-agent set to expire keys after a few minutes. I have not tried it, but my expectation is that it is possible to use key-based authentication without an agent. If it is true then a key usually has more entropy than a password (especially one easy to type), so no advantages of the latter. From my point of view, if an "intruder" may do something with a system during a short leave period then passwords should be considered as compromised and expiration period configured in ssh-agent does not matter. Instead of expiration timeout I would consider removing keys from ssh-agent on screen locker activation (explicitly by a shortcut or due to some idle time). Perhaps e.g. keepassxc as a ssh-agent can do it out of the box. For openssh is should be scriptable as well. I consider not adding to or removing a key from ssh-agent as a protection against my unintentional action. Tomas, I am sorry that I failed to express it clear enough, believing that the quote is enough for the context. From my point of view, ssh-agent allows to reduce number of passwords that are in the active pool. A pass phrase to a key gives access to multiple hosts. On the other hand, I consider adding password to a password manager as a kind of writing them down. Logins for remote systems must be kept somewhere anyway, you just do not need to type them frequently. Jeffrey, a hardware token is definitely is the next step in protection of ssh private keys and second factor for authentication. Of course, with some specific actions to not lost access in the case of token failure. As to client certificates, I may easily confuse everything, but from comments in various discussions I had impression that at least in some Europe (maybe Baltic and/or Nordic) countries people have to use smart cards to access some services provided by their states. Some of them arrange authentication on their own servers using the same client certificates.
[toc] | [prev] | [next] | [standalone]
| From | Chris Green <cl@isbd.net> |
|---|---|
| Date | 2024-12-20 10:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JVHuy-14Nc-11@gated-at.bofh.it> |
| In reply to | #275914 |
Max Nikulin <manikulin@gmail.com> wrote: > On 19/12/2024 15:56, Chris Green wrote: > > Horses for courses, I enter login passwords/passphrases quite frequently (lots of > > different systems that I ssh to) long, unmemorable, passwords would be > > useless. > > Generate a private key and add its public counterpart to > ~/.ssh/authorized_keys on remote machines. Locally running ssh-agent > allows to authenticate on remote machines without typing the pass phrase > for the private key for each connection. It is more secure than > passwords against brute force attacks. > Yes, but the passphrase for the private key then becomes your "password that you have to remember". The security of the actual connection is better as an intruder has to guess the key but IMHO I don't think that's the issue. I do in fact use ssh key based accessed for all my 'external' ssh connections, as you say this is more secure against direct attacks on the remote ssh server. However I did say in my post above "passwords/passphrases", I have to enter passphrases quite frequently for these ssh connections (I have agent set so the passphrase expires after a while), that's what I was talking about. -- Chris Green ·
[toc] | [prev] | [next] | [standalone]
| From | Michael Kjörling <c9bc136c6063@ewoof.net> |
|---|---|
| Date | 2024-12-18 10:20 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUYnL-sha-7@gated-at.bofh.it> |
| In reply to | #275846 |
On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright): > As you have to select the subset from some listboxes with a mouse, > I would guess that the step is designed to defeat key-logging. If someone has maliciously installed a keylogger, there's also likely some kind of screen recording software, so this seems like security theater. -- Michael Kjörling 🔗 https://michael.kjorling.se
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-18 10:20 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUYnL-sha-5@gated-at.bofh.it> |
| In reply to | #275861 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Dec 18, 2024 at 09:10:23AM +0000, Michael Kjörling wrote: > On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright): > > As you have to select the subset from some listboxes with a mouse, > > I would guess that the step is designed to defeat key-logging. > > If someone has maliciously installed a keylogger, there's also likely > some kind of screen recording software, so this seems like security > theater. Nowadays, with browsers, you can even get better than just "screen recording". Think, e.g. Selenium, which can record "clickstreams" on a browser with reference to the DOM objects (is usually used for testing, but hey). When doing "security analysis", I tend to lump "compromised client" into one category. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Michael Kjörling <c9bc136c6063@ewoof.net> |
|---|---|
| Date | 2024-12-18 10:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUYxr-slQ-5@gated-at.bofh.it> |
| In reply to | #275862 |
On 18 Dec 2024 10:15 +0100, from tomas@tuxteam.de: > When doing "security analysis", I tend to lump "compromised client" > into one category. Case in point: Microsoft Windows Recall. Plug that into your favorite web search engine if you aren't familiar with it, and read some of the tech media coverage of it. -- Michael Kjörling 🔗 https://michael.kjorling.se
[toc] | [prev] | [next] | [standalone]
| From | Chris Green <cl@isbd.net> |
|---|---|
| Date | 2024-12-18 18:20 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JV5Sh-y4C-1@gated-at.bofh.it> |
| In reply to | #275861 |
Michael Kjörling <c9bc136c6063@ewoof.net> wrote: > On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright): > > As you have to select the subset from some listboxes with a mouse, > > I would guess that the step is designed to defeat key-logging. > > If someone has maliciously installed a keylogger, there's also likely > some kind of screen recording software, so this seems like security > theater. > Yes, I think things like key loggers or even simple 'shoulder surfing' are the commonest ways of passwords being 'broken'. -- Chris Green ·
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2024-12-18 19:00 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JV6uZ-yph-5@gated-at.bofh.it> |
| In reply to | #275882 |
[Multipart message — attachments visible in raw view] — view raw
On Wed, Dec 18, 2024 at 04:55:59PM +0000, Chris Green wrote: > Michael Kjörling <c9bc136c6063@ewoof.net> wrote: > > On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright): > > > As you have to select the subset from some listboxes with a mouse, > > > I would guess that the step is designed to defeat key-logging. > > > > If someone has maliciously installed a keylogger, there's also likely > > some kind of screen recording software, so this seems like security > > theater. > > > Yes, I think things like key loggers or even simple 'shoulder surfing' > are the commonest ways of passwords being 'broken'. That's 1980s-1990s. These days it's service negligence and phishing. Cheers -- t
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-12-18 19:20 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JV6Om-yM3-7@gated-at.bofh.it> |
| In reply to | #275882 |
On Wed, Dec 18, 2024 at 12:10 PM Chris Green <cl@isbd.net> wrote: > > Michael Kjörling <c9bc136c6063@ewoof.net> wrote: > > On 17 Dec 2024 21:41 -0600, from deblis@lionunicorn.co.uk (David Wright): > > > As you have to select the subset from some listboxes with a mouse, > > > I would guess that the step is designed to defeat key-logging. > > > > If someone has maliciously installed a keylogger, there's also likely > > some kind of screen recording software, so this seems like security > > theater. > > > Yes, I think things like key loggers or even simple 'shoulder surfing' > are the commonest ways of passwords being 'broken'. Shoulder surfing has never been a problem for most users. People sense when someone is standing behind them and watching them. Homo sapiens developed the defense millions of years ago at a time when we were prey. (Gutmann discusses this in his book. I believe it is under the chapter on User Psychology). The useless password blanking/masking that hides typos is a solution looking for a problem. And it creates problems where none previously existed. The one that really irks me is when entering a Wifi password on a big screen tv. I would know if someone was looking in my bay window. And if I am really paranoid I can close the curtains. There's no need to blank/mask password characters. And I am aware Edward Snowden puts a blanket over his head and laptop when he unlocks his laptop. He is not a typical user. He is guarding against hidden cameras monitoring keyboard keystrokes. Password blanking/masking won't help him, either. Jeff
[toc] | [prev] | [next] | [standalone]
| From | Frank Jezzer <etphonehomefrance@gmail.com> |
|---|---|
| Date | 2024-12-22 17:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JWx05-1BFr-1@gated-at.bofh.it> |
| In reply to | #275846 |
On 2024-12-17, John Hasler <john@sugarbit.com> wrote: > Peter Hillier-Brook writes: >> the nonsense about about not changing them ignores the obvious. > > What is that? > >> My bank performs security checks by requesting a sub-set of my >> password. > > Sounds like a reason to find a new bank, in the meantime changing your > password after every such request. Surely they can't be hashing the > passwords properly if that practice is of any use. The problem is that your important information is not on your personal, password-protected machine. What good are your methods, as an Amuhrikan, if the IRS, your ISP, or the Social Security Administration is cracked? Or maybe a credit agency, as has already occurred. Nothing whatsoever. C'est là où le bat blesse. My French ISP was cracked, leaking my banking info. My medical insurance entity (French tiers payant) was cracked, also leaking my personal info. The cloud provider used by many French governmental agencies suffered a fire in Strasbourg in which my personal information was lost. All these things were beyond my control and had nothing to do with the data or password-protection on my computer. It's all useless babble here, if you are at all connected to the modern world.
[toc] | [prev] | [next] | [standalone]
| From | Jeffrey Walton <noloader@gmail.com> |
|---|---|
| Date | 2024-12-17 23:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUOeJ-jom-11@gated-at.bofh.it> |
| In reply to | #275844 |
On Tue, Dec 17, 2024 at 5:22 PM Peter Hillier-Brook <phb@hbsys.plus.com> wrote: > > On 17/12/2024 17:44, Michael Kjörling wrote: > > [...] > > Under the heading "Should I use a password manager?" the opening is: > > "Yes. Password managers are a good thing. They give you huge > > advantages in a world where there's far too many passwords for anyone > > to remember." > > I couldn't cope without PasswordSafe (thanks Mr. Schneier) and the > nonsense about about not changing them ignores the obvious. My bank > performs security checks by requesting a sub-set of my password. It > doesn't take a genius to work out that after several visits the complete > password can be deduced. Developer driven security is some of the worst security you will encounter in life. Web developers always seem to find a new way to dredge the bottom. Jeff
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <john@sugarbit.com> |
|---|---|
| Date | 2024-12-17 20:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JULqx-hFf-5@gated-at.bofh.it> |
| In reply to | #275841 |
Michael Kjörling writes: > Under the heading "Should I use a password manager?" the opening is: > "Yes. Password managers are a good thing. They give you huge > advantages in a world where there's far too many passwords for anyone > to remember." I use Firefox's built-in manager for "low threat" passwords such as that for my Reddit account (I also write them down). Most of my passwords fall in this class. Important passwords are recorded only in my "little black book". I also use a different user name for every Web account. One reason for writing down all your passwords (even if only on a list stored in your safe deposit box) is related to the item that started this thread: not making things difficult for whoever has to deal with your estate. -- John Hasler john@sugarbit.com Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
| From | debian-user@howorth.org.uk |
|---|---|
| Date | 2024-12-17 21:50 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUMFX-imO-1@gated-at.bofh.it> |
| In reply to | #275841 |
Michael Kjörling <c9bc136c6063@ewoof.net> wrote: > On 17 Dec 2024 06:45 +0100, from tomas@tuxteam.de: > >> Then follow Bruce Schneier's advice and*write them down*. > > > > Do you have a reference? > > > > I ask because I'm in the middle of a discussion (and that was my > > advice, too). Seeing what Schneier has to say on that would be very > > interesting. > > Not Schneier, but consider also the UK National Cyber Security > Centre's position on password managers: > https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers I tend to agree but I'll play Devil's Advocate here. If I was NCSC would I prefer to break a few password managers or millions of individual passwords? > Under the heading "Should I use a password manager?" the opening is: > "Yes. Password managers are a good thing. They give you huge > advantages in a world where there's far too many passwords for anyone > to remember." >
[toc] | [prev] | [next] | [standalone]
| From | Michael Kjörling <c9bc136c6063@ewoof.net> |
|---|---|
| Date | 2024-12-18 10:30 +0100 |
| Subject | Re: Writing passwords down |
| Message-ID | <JUYxr-slQ-7@gated-at.bofh.it> |
| In reply to | #275849 |
On 17 Dec 2024 20:44 +0000, from debian-user@howorth.org.uk: >> https://www.ncsc.gov.uk/blog-post/what-does-ncsc-think-password-managers > > I tend to agree but I'll play Devil's Advocate here. > > If I was NCSC would I prefer to break a few password managers or > millions of individual passwords? Counterpoint: Absent a password manager, people in general are _terrible_ at coming up with and remembering _good_ passwords. Especially the hundreds (or more) of passwords you can easily get to after being on the Internet for a while. And yes, a little black book can definitely be a password manager (assuming that you have some other way of generating good random passwords). In fact, for some people that might even be better than a digital solution, because a lot of people who have a poor grasp of digital information security _do_ still have a decent grasp of security surrounding physical possessions. They might not readily grasp the implications of handing their unlocked phone over to a stranger, but they probably do grasp the implications of handing their home keys over to the same stranger. -- Michael Kjörling 🔗 https://michael.kjorling.se
[toc] | [prev] | [next] | [standalone]
| From | debian-user@howorth.org.uk |
|---|---|
| Date | 2024-12-17 12:10 +0100 |
| Message-ID | <JUDCG-cTN-5@gated-at.bofh.it> |
| In reply to | #275807 |
songbird <songbird@anthive.com> wrote: > debian-user@howorth.org.uk wrote: > ... > > Why does your mother need to memorize all of your dead stepfather's > > identities? Just let them die with him. > > perhaps because the accounts are jointly owned and it > is much easier to just continue using the credentials as > they exist instead of having to set everything up all > over again for no real gain. (1) I assumed the OP was talking about more than 'accounts' (meaning financial accounts which I assume to be fairly few in number) but rather was talking about forums, web sites etc etc. (2) My wife and I have a joint account. My credentials and hers for the account are completely separate and different. (3) I now think the OP was trolling, so ...
[toc] | [prev] | [next] | [standalone]
Page 3 of 4 — ← Prev page 1 2 [3] 4 Next page →
Back to top | Article view | linux.debian.user
csiph-web