|
|
Log in / Subscribe / Register

Fedora's invisible passwords and visible squabbles

Fedora's invisible passwords and visible squabbles

Posted May 9, 2013 13:27 UTC (Thu) by Funcan (guest, #44209)
In reply to: Fedora's invisible passwords and visible squabbles by drag
Parent article: Fedora's invisible passwords and visible squabbles

Locking an account on /enough/ bad passwords makes perfect sense, otherwise dumb brute forcing starts to become too easy - assuming you can extract a list of login names from somewhere, trying a couple of hundred most common passwords on all of them has a good chance of getting a few hits (birthday paradox bites you in the ass).

If you allow complex passwords and have reasonably well educated users, then locking after 10 or 20 wrong attempts, rather than 3, might start to make sense. Locking for a sort time rather than indefinitely might start to make sense too. Fail2ban short term IP blocks might also make sense too


to post comments

Fedora's invisible passwords and visible squabbles

Posted May 9, 2013 15:18 UTC (Thu) by apoelstra (subscriber, #75205) [Link] (3 responses)

> If you allow complex passwords and have reasonably well educated users, then locking after 10 or 20 wrong attempts, rather than 3, might start to make sense. Locking for a sort time rather than indefinitely might start to make sense too. Fail2ban short term IP blocks might also make sense too

If you had said 100 or 200 attempts, I'd agree with you. No human is going to accidentally mess up a password that many times, any bad guy who can guess the password in fewer tries knows too much anyway (you already have compromised security), and brute forcing is completely blocked.

Alternately, blocking unilaterally for 15 or 30 seconds after every bad attempt would also prevent brute-forcing, as well as be extremely irritating to human bad guys.

Fedora's invisible passwords and visible squabbles

Posted May 9, 2013 16:36 UTC (Thu) by drag (guest, #31333) [Link]

All the difference between have 3 tries and 200 tries is that it takes a attacker a few seconds longer to lock out all the users and administrators. ;)

Fedora's invisible passwords and visible squabbles

Posted May 15, 2013 14:14 UTC (Wed) by hummassa (guest, #307) [Link] (1 responses)

Apple does the right thing with respect to this: throttle exponentially against the number of tries. 10s, 30s, 1.5min, 4.5min, 13.5min, 40.5min and so on.

Fedora's invisible passwords and visible squabbles

Posted May 16, 2013 13:21 UTC (Thu) by callegar (guest, #16148) [Link]

No, not at all. It is quite irritating when you leave your ipad around to see that someone had fun in locking it for almost 15'.

Really, this does not make any sense. To avoid brute force attacks a few seconds are more than enough: 100000 trials * 36 sec = 3600000 sec = 3600h = half a year > average time between recommended password changes.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds