Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #275848
| From | Nicholas Geovanis <nickgeovanis@gmail.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Writing passwords down [was: a passwordless operating system] |
| Date | 2024-12-17 21:10 +0100 |
| Message-ID | <JUM3f-i9u-7@gated-at.bofh.it> (permalink) |
| References | (4 earlier) <JUyCZ-9Eu-1@gated-at.bofh.it> <JUIiZ-fKY-3@gated-at.bofh.it> <JUJyp-gvF-5@gated-at.bofh.it> <JUJI6-gzH-17@gated-at.bofh.it> <JUKut-h5C-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
On Tue, Dec 17, 2024, 12:24 PM <tomas@tuxteam.de> wrote: > On Tue, Dec 17, 2024 at 12:37:33PM -0500, Jeffrey Walton wrote: > > On Tue, Dec 17, 2024 at 12:29 PM <tomas@tuxteam.de> wrote: > > > > > > On Tue, Dec 17, 2024 at 10:59:40AM -0500, Michael Stone wrote: > > > > On Tue, Dec 17, 2024 at 06:45:05AM +0100, tomas@tuxteam.de wrote: > > > > > Do you have a reference? > > > > > > > > > > I ask because I'm in the middle of a discussion (and that was my > advice, > > > > > too). Seeing what Schneier has to say on that would be very > interesting. > > > > > > > > All of this advice is overly simplistic. The right answer depends on > > > > understanding your threats and making a conscious decision what > risks you > > > > want to mitigate [...] > > > > > > I know, I know. My introductory sentence is almost literally yours. > > > > > > As times shift, threat models shift accordingly. Back then, when > > > computers and environments were more shared, post-its and shoulder > > > surfing were the main password leak threat, in-between it was the > > > (clear text) transport, these days it's probably phishing and > > > server-side breaches, which -- hopefully! -- yield a database of > > > salted hashes, in which case strong passwords are vital. > > > > > > I'm still very interested in those references, not to follow them > > > blindly, but because they may contain insights I haven't had myself. > > > Especially in the case of Schneier, I'm doubly eager to listen. > > > > Schneier is security on training wheels. (Not to impune his work). It > > is a good introduction, but it is written for a different audience > His earlier book on cryptography was for a while the best source for people who wrote code. I guess his BlowFish cipher has not stood up so well over longer time. He started his career in the Chicago area at ATT. Perfect for my purposes. I'm trying to get people to understand that > security is relative (to everything else around it, i.e. the famous > "threat model"). If they end up digesting Schneier's "process, not > product", I'm happy. > Reading the US DoD Orange Book in 1990, we realized that a server secured at the A level was essentially unusable for its purpose. At best a single-user single-purpose machine. And that physical security is the foundation of all other security, without it all else is meaningless. So from a certain perspective, all of our efforts were futile :-) The "Rainbow Books" have been freely available online for some years. > If you really want to satisfy your security related hunger, then read > > Gutmann's Engineering Security[1] or Ross Anderson's Security > > Engineering.[2] I prefer Gutmann because it is so well cited. I often > > pull the cited papers and read them for myself. > Papers by Bell and LaPadula on MAC and DAC are foundational, they used to be freely available online. The original theoretical basis of the SElinux model. Gutmann was mentioned in this thread. Anderson wrote in CACM's "Inside > Risks", right? > > Cheers > -- > t >
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 09:00 +0100
Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-15 14:50 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-15 15:30 +0100
Re: a passwordless operating system songbird <songbird@anthive.com> - 2024-12-17 05:00 +0100
Re: a passwordless operating system John Hasler <john@sugarbit.com> - 2024-12-17 05:30 +0100
Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 06:50 +0100
Re: Writing passwords down [was: a passwordless operating system] "Loris Bennett" <loris.bennett@fu-berlin.de> - 2024-12-17 08:30 +0100
Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 08:50 +0100
Re: Writing passwords down [was: a passwordless operating system] Mike Castle <dalgoda+debian@gmail.com> - 2024-12-17 18:00 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 15:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Lee <ler762@gmail.com> - 2024-12-17 15:40 +0100
Re: libreoffice/openoffice system theme <tomas@tuxteam.de> - 2024-12-17 16:00 +0100
Re: Writing passwords down [was: a passwordless operating system] Michael Stone <mstone@debian.org> - 2024-12-17 17:10 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:30 +0100
Re: Writing passwords down [was: a passwordless operating system] "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-17 18:40 +0100
Re: Writing passwords down [was: a passwordless operating system] <tomas@tuxteam.de> - 2024-12-17 18:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Jeffrey Walton <noloader@gmail.com> - 2024-12-17 18:40 +0100
Re: Writing passwords down [was: a passwordless operating system] tomas@tuxteam.de - 2024-12-17 19:30 +0100
Re: Writing passwords down [was: a passwordless operating system] Nicholas Geovanis <nickgeovanis@gmail.com> - 2024-12-17 21:10 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-17 18:50 +0100
Re: Writing passwords down Peter Hillier-Brook <phb@hbsys.plus.com> - 2024-12-17 20:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:50 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-18 06:00 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 11:00 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 19:00 +0100
Re: Writing passwords down "James H. H. Lampert" <jamesl@touchtonecorp.com> - 2024-12-18 19:10 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 20:10 +0100
Re: Writing passwords down pocket@homemail.com - 2024-12-18 21:20 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 19:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-19 06:00 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 20:30 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-18 23:10 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:20 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-19 02:30 +0100
Re: Writing passwords down Karen Lewellen <klewellen@shellworld.net> - 2024-12-19 02:40 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-19 10:20 +0100
Re: Writing passwords down Joe <joe@jretrading.com> - 2024-12-19 12:20 +0100
Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-20 04:30 +0100
Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-20 05:40 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-20 05:40 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-20 06:10 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:50 +0100
Re: Writing passwords down George at Clug <Clug@goproject.info> - 2024-12-21 01:40 +0100
Re: Writing passwords down Max Nikulin <manikulin@gmail.com> - 2024-12-21 04:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-20 10:30 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:20 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 10:20 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
Re: Writing passwords down Chris Green <cl@isbd.net> - 2024-12-18 18:20 +0100
Re: Writing passwords down <tomas@tuxteam.de> - 2024-12-18 19:00 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-18 19:20 +0100
Re: Writing passwords down Frank Jezzer <etphonehomefrance@gmail.com> - 2024-12-22 17:30 +0100
Re: Writing passwords down Jeffrey Walton <noloader@gmail.com> - 2024-12-17 23:30 +0100
Re: Writing passwords down John Hasler <john@sugarbit.com> - 2024-12-17 20:30 +0100
Re: Writing passwords down debian-user@howorth.org.uk - 2024-12-17 21:50 +0100
Re: Writing passwords down Michael Kjörling <c9bc136c6063@ewoof.net> - 2024-12-18 10:30 +0100
Re: a passwordless operating system debian-user@howorth.org.uk - 2024-12-17 12:10 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-15 15:40 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 08:50 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 08:50 +0100
Re: a passwordless operating system Andy Smith <andy@strugglers.net> - 2024-12-16 09:00 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system Jeffrey Walton <noloader@gmail.com> - 2024-12-16 09:10 +0100
Re: a passwordless operating system 🦓 <czyborra@gmail.com> - 2024-12-16 09:20 +0100
csiph-web