Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #210641 > unrolled thread

How to have password shown?

Started byRodolfo Medina <rodolfo.medina@gmail.com>
First post2019-07-03 13:30 +0200
Last post2019-07-03 15:20 +0200
Articles 20 on this page of 48 — 19 participants

Back to article view | Back to linux.debian.user


Contents

  How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 13:30 +0200
    Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 14:20 +0200
      Re: How to have password shown? Nicolas George <george@nsup.org> - 2019-07-03 14:20 +0200
      Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 14:30 +0200
        Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 14:40 +0200
          Re: How to have password shown? deloptes <deloptes@gmail.com> - 2019-07-04 04:00 +0200
    Re: How to have password shown? <tomas@tuxteam.de> - 2019-07-03 14:20 +0200
      Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 15:10 +0200
        Re: How to have password shown? deloptes <deloptes@gmail.com> - 2019-07-04 04:00 +0200
          Re: How to have password shown? Curt <curty@free.fr> - 2019-07-04 14:50 +0200
      Re: How to have password shown? Jonas Smedegaard <jonas@jones.dk> - 2019-07-03 15:10 +0200
    Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 14:20 +0200
      Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 14:20 +0200
        Re: How to have password shown? Carl Fink <carl@finknetwork.com> - 2019-07-03 15:20 +0200
          Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 15:30 +0200
            Re: How to have password shown? Reco <recoverym4n@enotuniq.net> - 2019-07-03 17:40 +0200
              Re: How to have password shown? <tomas@tuxteam.de> - 2019-07-03 18:40 +0200
              Re: How to have password shown? David Wright <deblis@lionunicorn.co.uk> - 2019-07-03 22:10 +0200
              Re: How to have password shown? Richard Hector <richard@walnut.gen.nz> - 2019-07-05 06:40 +0200
                Re: How to have password shown? Reco <recoverym4n@enotuniq.net> - 2019-07-05 08:50 +0200
                  Re: How to have password shown? Carl Fink <carlf@panix.com> - 2019-07-05 16:30 +0200
                    Re: How to have password shown? Reco <recoverym4n@enotuniq.net> - 2019-07-05 21:40 +0200
      Re: How to have password shown? <tomas@tuxteam.de> - 2019-07-03 14:20 +0200
    Re: How to have password shown? Håkon Alstadheim <hakon@alstadheim.priv.no> - 2019-07-03 14:30 +0200
      Re: How to have password shown? Nicolas George <george@nsup.org> - 2019-07-03 14:50 +0200
        Re: How to have password shown? Nicolas George <george@nsup.org> - 2019-07-03 15:00 +0200
          Re: How to have password shown? Nicolas George <george@nsup.org> - 2019-07-03 15:10 +0200
          Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 15:10 +0200
          Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 15:10 +0200
        Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 15:00 +0200
          Re: How to have password shown? Stefan Monnier <monnier@iro.umontreal.ca> - 2019-07-03 19:30 +0200
          Re: How to have password shown? deloptes <deloptes@gmail.com> - 2019-07-04 04:10 +0200
      Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 14:50 +0200
        Re: How to have password shown? Jonas Smedegaard <jonas@jones.dk> - 2019-07-03 15:30 +0200
          Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 15:40 +0200
            Re: How to have password shown? Brian <ad44@cityscape.co.uk> - 2019-07-03 16:10 +0200
              Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 16:20 +0200
                Re: How to have password shown? andreimpopescu@gmail.com - 2019-07-03 16:40 +0200
                  Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 16:40 +0200
                    Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 17:10 +0200
              Re: How to have password shown? Dave Sherohman <dave@sherohman.org> - 2019-07-04 13:00 +0200
            Re: How to have password shown? <tomas@tuxteam.de> - 2019-07-03 17:10 +0200
              Re: How to have password shown? tomas@tuxteam.de - 2019-07-03 17:20 +0200
                Re: How to have password shown? Greg Wooledge <wooledg@eeg.ccf.org> - 2019-07-03 17:30 +0200
              Re: How to have password shown? Nicolas George <george@nsup.org> - 2019-07-03 17:20 +0200
              Re: How to have password shown? Rodolfo Medina <rodolfo.medina@gmail.com> - 2019-07-03 17:30 +0200
      Re: How to have password shown? Renato Gallo <renato@aster-lab.com> - 2019-07-03 14:50 +0200
        Re: How to have password shown? <tomas@tuxteam.de> - 2019-07-03 15:20 +0200

Page 1 of 3  [1] 2 3  Next page →


#210641 — How to have password shown?

FromRodolfo Medina <rodolfo.medina@gmail.com>
Date2019-07-03 13:30 +0200
SubjectHow to have password shown?
Message-ID<yfLCx-596-1@gated-at.bofh.it>
Hi all...

Is there any a way to have my user-password shown when logging into Debian in
tty console, or also within X system when changing to root?  It is for my old
father...  it'd be easier for him to see what he's typing.  In internet I found
some procedures to have asterisks shown; would it be possible to have a clear
text as well?  Maybe it isn't as I understand...

Thanks for any help,

Cheers,

Rodolfo

[toc] | [next] | [standalone]


#210642

FromRenato Gallo <renato@aster-lab.com>
Date2019-07-03 14:20 +0200
Message-ID<yfMoV-5EV-3@gated-at.bofh.it>
In reply to#210641
.... and that's soooo good security-wise

Renato Gallo 

----- Original Message -----
From: tomas@tuxteam.de
To: "Rodolfo Medina" <rodolfo.medina@gmail.com>
Cc: "debian-user" <debian-user@lists.debian.org>
Sent: Wednesday, July 3, 2019 2:12:22 PM
Subject: Re: How to have password shown?

On Wed, Jul 03, 2019 at 11:24:54AM +0000, Rodolfo Medina wrote:
> Hi all...
> 
> Is there any a way to have my user-password shown when logging into Debian in
> tty console, or also within X system when changing to root?  It is for my old
> father...  it'd be easier for him to see what he's typing.  In internet I found
> some procedures to have asterisks shown; would it be possible to have a clear
> text as well?  Maybe it isn't as I understand...

I think /bin/login isn't set up to allow that (at least that's what a cursory
reading of its man page tells me). I fear the only way for you would be to
modify its source and recompile...

Cheers
-- tomás

[toc] | [prev] | [next] | [standalone]


#210645

FromNicolas George <george@nsup.org>
Date2019-07-03 14:20 +0200
Message-ID<yfMoW-5EV-11@gated-at.bofh.it>
In reply to#210642

[Multipart message — attachments visible in raw view] — view raw

Renato Gallo (12019-07-03):
> .... and that's soooo good security-wise

The good practice, security-wise, is to start by understanding the
situation and the threat.

Regards,

-- 
  Nicolas George

[toc] | [prev] | [next] | [standalone]


#210650

FromRodolfo Medina <rodolfo.medina@gmail.com>
Date2019-07-03 14:30 +0200
Message-ID<yfMyB-5HZ-5@gated-at.bofh.it>
In reply to#210642
Renato Gallo <renato@aster-lab.com> writes:

> .... and that's soooo good security-wise
>
> Renato Gallo 


Renato, thanks...

but didn't I clearly specify the special circumstances of my (strange, I agree)
request...?  It seems to me that I did...

Cheers,

Rodolfo

[toc] | [prev] | [next] | [standalone]


#210653

FromRenato Gallo <renato@aster-lab.com>
Date2019-07-03 14:40 +0200
Message-ID<yfMIh-5Lb-13@gated-at.bofh.it>
In reply to#210650
You did but nevertheless to give such an option would be a bad idea 
(someone could be crazy enough to be tempted to use it).

Renato Gallo 

----- Original Message -----
From: "Rodolfo Medina" <rodolfo.medina@gmail.com>
To: "debian-user" <debian-user@lists.debian.org>
Sent: Wednesday, July 3, 2019 2:26:24 PM
Subject: Re: How to have password shown?

Renato Gallo <renato@aster-lab.com> writes:

> .... and that's soooo good security-wise
>
> Renato Gallo 


Renato, thanks...

but didn't I clearly specify the special circumstances of my (strange, I agree)
request...?  It seems to me that I did...

Cheers,

Rodolfo

[toc] | [prev] | [next] | [standalone]


#210699

Fromdeloptes <deloptes@gmail.com>
Date2019-07-04 04:00 +0200
Message-ID<yfZcu-4I4-1@gated-at.bofh.it>
In reply to#210653
Renato Gallo wrote:

> You did but nevertheless to give such an option would be a bad idea
> (someone could be crazy enough to be tempted to use it).

For his fathers computer - are you serious? I guess his father does not
care.

[toc] | [prev] | [next] | [standalone]


#210643

From<tomas@tuxteam.de>
Date2019-07-03 14:20 +0200
Message-ID<yfMoV-5EV-5@gated-at.bofh.it>
In reply to#210641

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jul 03, 2019 at 11:24:54AM +0000, Rodolfo Medina wrote:
> Hi all...
> 
> Is there any a way to have my user-password shown when logging into Debian in
> tty console, or also within X system when changing to root?  It is for my old
> father...  it'd be easier for him to see what he's typing.  In internet I found
> some procedures to have asterisks shown; would it be possible to have a clear
> text as well?  Maybe it isn't as I understand...

I think /bin/login isn't set up to allow that (at least that's what a cursory
reading of its man page tells me). I fear the only way for you would be to
modify its source and recompile...

Cheers
-- tomás

[toc] | [prev] | [next] | [standalone]


#210661

FromRenato Gallo <renato@aster-lab.com>
Date2019-07-03 15:10 +0200
Message-ID<yfNbk-6bN-15@gated-at.bofh.it>
In reply to#210643
Fingerprints are a good option

Renato Gallo 

----- Original Message -----
From: "Jonas Smedegaard" <jonas@jones.dk>
To: "debian-user" <debian-user@lists.debian.org>
Sent: Wednesday, July 3, 2019 3:00:04 PM
Subject: Re: How to have password shown?

Quoting tomas@tuxteam.de (2019-07-03 14:12:22)
> On Wed, Jul 03, 2019 at 11:24:54AM +0000, Rodolfo Medina wrote:
> > Is there any a way to have my user-password shown when logging into 
> > Debian in tty console, or also within X system when changing to 
> > root?  It is for my old father...  it'd be easier for him to see 
> > what he's typing.  In internet I found some procedures to have 
> > asterisks shown; would it be possible to have a clear text as well?  
> > Maybe it isn't as I understand...
> 
> I think /bin/login isn't set up to allow that (at least that's what a 
> cursory reading of its man page tells me). I fear the only way for you 
> would be to modify its source and recompile...

I am aware that I am not really addressing the original poster's 
question, but possibly helpful anyway:

I can suggest to consider options where typing a password is replaced by 
presence of something physically, using packages like these:

libpam-biometric / libpam-fprintd - fingerprint
libpam-blue - bluetooth device
libpam-p11 / libpam-pkcs11 / libpam-poldi - smartcard
libpam-ssh-agent-auth - user-to-root access
libpam-yubico / libpam-u2f - hardware dongle
libpam-script - custom routine

I am curious which solutions you end up with for your father, as I am 
working on streamined¹ setup of similar use cases.

I would also appreciate constructive² opinions and feedback from anyone 
experienced with these various ways of sidestepping password-based 
system login.


 - Jonas

¹ See https://box.redpill.dk/ if curious

² Posts blindly assuming that all Debian must be treated as a fortress 
will be silently deleted

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/

 [x] quote me freely  [ ] ask before reusing  [ ] keep private

[toc] | [prev] | [next] | [standalone]


#210700

Fromdeloptes <deloptes@gmail.com>
Date2019-07-04 04:00 +0200
Message-ID<yfZcu-4I4-3@gated-at.bofh.it>
In reply to#210661
Renato Gallo wrote:

> Fingerprints are a good option
> 
> Renato Gallo
> 

No, they are not and it was explained previously why

[toc] | [prev] | [next] | [standalone]


#210712

FromCurt <curty@free.fr>
Date2019-07-04 14:50 +0200
Message-ID<yg9lw-2uj-5@gated-at.bofh.it>
In reply to#210700
On 2019-07-04, deloptes <deloptes@gmail.com> wrote:
> Renato Gallo wrote:
>
>> Fingerprints are a good option
>> 
>> Renato Gallo
>> 
>
> No, they are not and it was explained previously why
>

Sure they are (depending on the use case/implementation). These things are
completely comparative and situational and your statement completely
unqualified and universal. The OP desired having the password revealed in
plaintext on the terminal/console.  Another person thought an insecure password
like 12345 might do the trick.  Still another suggested a passwordless login
for the OP's venerable paternal element. I was asking myself how the
blind/visually impaired handle the problem.  And the cognitively impaired. And
those suffering from motor impairments which might render any "fine" use of the
keyboard a painstaking affair. 

Reco's objections to fingerprints as an authentication method, to which you
might be alluding above, called to mind what I'd previously heard from Schneier
concerning biometrics years ago. Let's see what he said in 2009 (update to an
essay written in 1998).

https://www.schneier.com/blog/archives/2009/01/biometrics.html

 And a stolen biometric can fool some systems. It can be as easy as cutting out
 a signature, pasting it onto a contract, and then faxing the page to someone.
 The person on the other end doesn't know that the signature isn't valid because
 he didn't see it fixed onto the page. Remote logins by fingerprint fail in the
 same way. If there's no way to verify the print came from an actual reader, not
 from a stored computer file, the system is much less secure.

 A more secure system is to use a fingerprint to unlock your mobile phone or
 computer. Because there is a trusted path from the fingerprint reader to the
 stored fingerprint the system uses to compare, an attacker can't inject a
 previously stored print as easily as he can cut and paste a signature. A photo
 on an ID card works the same way: the verifier can compare the face in front of
 him with the face on the card.

[toc] | [prev] | [next] | [standalone]


#210663

FromJonas Smedegaard <jonas@jones.dk>
Date2019-07-03 15:10 +0200
Message-ID<yfNbk-6bN-9@gated-at.bofh.it>
In reply to#210643

[Multipart message — attachments visible in raw view] — view raw

Quoting tomas@tuxteam.de (2019-07-03 14:12:22)
> On Wed, Jul 03, 2019 at 11:24:54AM +0000, Rodolfo Medina wrote:
> > Is there any a way to have my user-password shown when logging into 
> > Debian in tty console, or also within X system when changing to 
> > root?  It is for my old father...  it'd be easier for him to see 
> > what he's typing.  In internet I found some procedures to have 
> > asterisks shown; would it be possible to have a clear text as well?  
> > Maybe it isn't as I understand...
> 
> I think /bin/login isn't set up to allow that (at least that's what a 
> cursory reading of its man page tells me). I fear the only way for you 
> would be to modify its source and recompile...

I am aware that I am not really addressing the original poster's 
question, but possibly helpful anyway:

I can suggest to consider options where typing a password is replaced by 
presence of something physically, using packages like these:

libpam-biometric / libpam-fprintd - fingerprint
libpam-blue - bluetooth device
libpam-p11 / libpam-pkcs11 / libpam-poldi - smartcard
libpam-ssh-agent-auth - user-to-root access
libpam-yubico / libpam-u2f - hardware dongle
libpam-script - custom routine

I am curious which solutions you end up with for your father, as I am 
working on streamined¹ setup of similar use cases.

I would also appreciate constructive² opinions and feedback from anyone 
experienced with these various ways of sidestepping password-based 
system login.


 - Jonas

¹ See https://box.redpill.dk/ if curious

² Posts blindly assuming that all Debian must be treated as a fortress 
will be silently deleted

-- 
 * Jonas Smedegaard - idealist & Internet-arkitekt
 * Tlf.: +45 40843136  Website: http://dr.jones.dk/

 [x] quote me freely  [ ] ask before reusing  [ ] keep private

[toc] | [prev] | [next] | [standalone]


#210644

FromRenato Gallo <renato@aster-lab.com>
Date2019-07-03 14:20 +0200
Message-ID<yfMoW-5EV-13@gated-at.bofh.it>
In reply to#210641
one of the worst ideas I've ever heard since 1974

read this https://en.wikipedia.org/wiki/Shoulder_surfing_(computer_security)

Renato Gallo 

System Engineer 
sede legale e operativa: Via Privata Cefalonia, 14 - 20156 - Milano (MI) 
Tel. +39 02 - 87049490 
Fax +39 02 - 48677349 
Mobile. +39 342 - 6350524 
Wi | FreeNumbers: https://freenumbers.way-interactive.com 
Wi | SMS: https://sms.way-interactive.com 
Wi | Voip: https://voip.way-interactive.com 
Asterweb: http://www.asterweb.org 

Le informazioni contenute in questo messaggio e negli eventuali allegati sono riservate e per uso esclusivo del destinatario. 
Persone diverse dallo stesso non possono copiare o distribuire il messaggio a terzi. 
Chiunque riceva questo messaggio per errore è pregato di distruggerlo e di informare immediatamente [ mailto:info@sigmaware.it | info@ ] asterweb.org

----- Original Message -----
From: "Rodolfo Medina" <rodolfo.medina@gmail.com>
To: "debian-user" <debian-user@lists.debian.org>
Sent: Wednesday, July 3, 2019 1:24:54 PM
Subject: How to have password shown?

Hi all...

Is there any a way to have my user-password shown when logging into Debian in
tty console, or also within X system when changing to root?  It is for my old
father...  it'd be easier for him to see what he's typing.  In internet I found
some procedures to have asterisks shown; would it be possible to have a clear
text as well?  Maybe it isn't as I understand...

Thanks for any help,

Cheers,

Rodolfo

[toc] | [prev] | [next] | [standalone]


#210646

FromRenato Gallo <renato@aster-lab.com>
Date2019-07-03 14:20 +0200
Message-ID<yfMoW-5EV-17@gated-at.bofh.it>
In reply to#210644
If you are living alone in a bunker under an alien planet surface ok "shoulder surfing is not an issue"

Renato Gallo 

----- Original Message -----
From: "tomas" <tomas@tuxteam.de>
To: "renato" <renato@aster-lab.com>
Cc: "Rodolfo Medina" <rodolfo.medina@gmail.com>, "debian-user" <debian-user@lists.debian.org>
Sent: Wednesday, July 3, 2019 2:14:14 PM
Subject: Re: How to have password shown?

On Wed, Jul 03, 2019 at 02:10:50PM +0200, Renato Gallo wrote:
> one of the worst ideas I've ever heard since 1974
> 
> read this https://en.wikipedia.org/wiki/Shoulder_surfing_(computer_security)

I assume Rodolfo knows all that. Perhaps the context is one where
.

Security is not about blindly following rules :^)

Cheers
-- t

[toc] | [prev] | [next] | [standalone]


#210665

FromCarl Fink <carl@finknetwork.com>
Date2019-07-03 15:20 +0200
Message-ID<yfNkZ-6eK-1@gated-at.bofh.it>
In reply to#210646
On Wed, Jul 03, 2019 at 02:17:45PM +0200, Renato Gallo wrote:
> If you are living alone in a bunker under an alien planet surface ok "shoulder surfing is not an issue"

If someone is shoulder-surfing, and really wants the password, she will just
watch your fingers, Renato. Slightly harder but not hard, especially with
video cameras the size of a grape now being easily available.
-- 
Carl Fink                           nitpicking@nitpicking.com 

Read John Grant's book, Corrupted Science: http://a.co/9UsUoGu 
Dedicated to ... Carl Fink!

[toc] | [prev] | [next] | [standalone]


#210667

FromRenato Gallo <renato@aster-lab.com>
Date2019-07-03 15:30 +0200
Message-ID<yfNuF-6hU-5@gated-at.bofh.it>
In reply to#210665
Would be nice for any cracker if it could be possible to get access by shoulder surfing my fingerprint reader ;)

Renato Gallo 


----- Original Message -----
From: "Carl Fink" <carl@finknetwork.com>
To: "debian-user" <debian-user@lists.debian.org>
Sent: Wednesday, July 3, 2019 3:10:18 PM
Subject: Re: How to have password shown?

On Wed, Jul 03, 2019 at 02:17:45PM +0200, Renato Gallo wrote:
> If you are living alone in a bunker under an alien planet surface ok "shoulder surfing is not an issue"

If someone is shoulder-surfing, and really wants the password, she will just
watch your fingers, Renato. Slightly harder but not hard, especially with
video cameras the size of a grape now being easily available.
-- 
Carl Fink                           nitpicking@nitpicking.com 

Read John Grant's book, Corrupted Science: http://a.co/9UsUoGu 
Dedicated to ... Carl Fink!

[toc] | [prev] | [next] | [standalone]


#210682

FromReco <recoverym4n@enotuniq.net>
Date2019-07-03 17:40 +0200
Message-ID<yfPwu-7sw-13@gated-at.bofh.it>
In reply to#210667
	Hi.

On Wed, Jul 03, 2019 at 03:29:27PM +0200, Renato Gallo wrote:
> Would be nice for any cracker if it could be possible to get access by shoulder surfing my fingerprint reader ;)

Using a fingerprint instead of a password is a bad idea. Using a
fingerprint instead of a username - that's OK.

You can change a password if it's leaked.
You cannot change your fingerprint (legally, that is). And one leaves
fingerprints on every surface one touches.

Reco

[toc] | [prev] | [next] | [standalone]


#210687

From<tomas@tuxteam.de>
Date2019-07-03 18:40 +0200
Message-ID<yfQsx-81c-11@gated-at.bofh.it>
In reply to#210682

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jul 03, 2019 at 06:34:28PM +0300, Reco wrote:
> 	Hi.
> 
> On Wed, Jul 03, 2019 at 03:29:27PM +0200, Renato Gallo wrote:
> > Would be nice for any cracker if it could be possible to get access by shoulder surfing my fingerprint reader ;)
> 
> Using a fingerprint instead of a password is a bad idea. Using a
> fingerprint instead of a username - that's OK.
> 
> You can change a password if it's leaked.
> You cannot change your fingerprint (legally, that is). And one leaves
> fingerprints on every surface one touches.

Good point :-)

This [1] (alas, in German) describes how the CCC lifted (and published)
the fingerprint of Wolfgang Schäuble [2], at that time German minister
of the Interior, a pretty sharp advocate of authoritarian security.

Now that was 2008: they had to get hold of a glass he had in his hands.
These days, reportedly, a good digital camera is enough for that.

Cheers

[1] https://www.heise.de/security/meldung/CCC-publiziert-die-Fingerabdruecke-von-Wolfgang-Schaeuble-Update-193732.html
[2] https://en.wikipedia.org/wiki/Wolfgang_Sch%C3%A4uble

-- tomas "never use biometric data as a strong identifier"

[toc] | [prev] | [next] | [standalone]


#210693

FromDavid Wright <deblis@lionunicorn.co.uk>
Date2019-07-03 22:10 +0200
Message-ID<yfTJM-1FL-7@gated-at.bofh.it>
In reply to#210682
On Wed 03 Jul 2019 at 18:34:28 (+0300), Reco wrote:
> On Wed, Jul 03, 2019 at 03:29:27PM +0200, Renato Gallo wrote:
> > Would be nice for any cracker if it could be possible to get access by shoulder surfing my fingerprint reader ;)

One hears gruesome stories about fingerprint security.

> Using a fingerprint instead of a password is a bad idea. Using a
> fingerprint instead of a username - that's OK.
> 
> You can change a password if it's leaked.
> You cannot change your fingerprint (legally, that is). And one leaves
> fingerprints on every surface one touches.

And on occasions it can be hard to come up with a good impression;
for example, after a week or two's rock climbing in the Cuillin of Skye,
the tips of your fingers are worn smooth by the gabbro.

But it does disappoint me that there aren't more options for how
characters are reflected (or not) when typing passwords; not
forgetting passphrases either. LUKS types asterisks under some
circumstances and nothing under others. I haven't managed to pin down
how that decision is made or which binary makes it.

You can make shoulder-surfing more difficult by overwriting each
character a fraction of a second after it's typed.

Cheers,
David.

[toc] | [prev] | [next] | [standalone]


#210743

FromRichard Hector <richard@walnut.gen.nz>
Date2019-07-05 06:40 +0200
Message-ID<ygoaR-44N-1@gated-at.bofh.it>
In reply to#210682

[Multipart message — attachments visible in raw view] — view raw

On 4/07/19 3:34 AM, Reco wrote:
> You cannot change your fingerprint (legally, that is).

Say what? Are you saying there's a jurisdiction in which it's illegal
for me to sand off, cut, or otherwise mutillate my own fingerprint?

Richard

[toc] | [prev] | [next] | [standalone]


#210745

FromReco <recoverym4n@enotuniq.net>
Date2019-07-05 08:50 +0200
Message-ID<ygqcG-5ex-1@gated-at.bofh.it>
In reply to#210743
	Hi.

On Fri, Jul 05, 2019 at 04:33:30PM +1200, Richard Hector wrote:
> On 4/07/19 3:34 AM, Reco wrote:
> > You cannot change your fingerprint (legally, that is).
> 
> Say what? Are you saying there's a jurisdiction in which it's illegal
> for me to sand off, cut, or otherwise mutillate my own fingerprint?

Depends on where you live and on what you're doing for the living.
I imagine a government employee (say, military or law enforment) will
have a hard time explaining "accidental" fingerprint mutilation on all
ten fingers.
Last time I travelled to England - they took my fingerprints beforehand,
and checked them at Heathrow's customs. Suffice to say I'd be sent back
home on a nearest airplane if they haven't match.

Reco

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web