Fedora's invisible passwords and visible squabbles
Fedora's invisible passwords and visible squabbles
Posted May 9, 2013 15:07 UTC (Thu) by Baylink (guest, #755)Parent article: Fedora's invisible passwords and visible squabbles
Is a change in password-entry-handling warranted? And is Anaconda suficiently "core" to Fedora that that question should drive or be driven by a distribution-wide policy, as opposed to being a "preserve the desires of the package maintainers" issue?
My inclination on the latter is "yes", though admittedly, I haven't used Anaconda since RH8; you have no choice about the installer, the distribution release manager picks that for you; I can't think of anything else -- even the kernel, about which you sometimes get a choice -- that is so core to a distribution as its installer package. That being the case, I don't think it at all unreasonable to construe that as a core package, and expect that policies it sets are distribution wide policies, rather than the whims of a specific package maintainer.
The more fundamental question, though, is the first: is a change in default password-entry visibility policy justified? It is my understanding that one of the driving forces behind this change was an opinion put forth by security consultant Bruce Schneier.
Bruce has recanted that opinion in later writings, so to the extent that it was such a driving force, it's clearly time to reconsider. That said, it's substantially easier -- an order of magnitude, if not two -- to shoulder-surf off a display (think "binoculars", if not "HD security webcams" "Freeze! And Enhance!" :-).
I personally tend to like to check that box that says "show my password". But *I want the box*; *I* know if someone is near me, or if my monitor is visible from useful angles; the computer... so doesn't.
IMO: The box should be there, and by default, it should be unchecked. Those who note that asterisks are bad are also correct; knowing the length of the password substantially reduces the effort to crack it.
It's possible such a single-use password is not the low-hanging fruit, but we do know what makes it *less* secure, and there's no sense volunteering to do those things.
