|
|
Log in / Subscribe / Register

Fedora's invisible passwords and visible squabbles

Fedora's invisible passwords and visible squabbles

Posted May 9, 2013 16:34 UTC (Thu) by drag (guest, #31333)
In reply to: Fedora's invisible passwords and visible squabbles by mitr
Parent article: Fedora's invisible passwords and visible squabbles

> I think it's exactly the other way around: systems should lock users out, at least for some time, on incorrect attempts; if they do, the passwords can be much shorter and easier to enter.

At any place I worked at that had such password policies I could lock out EVERYBODY in the entire corporation with a simple shell script.

How would you like it if everybody got locked out of their accounts? CEO, IT, business, etc etc. Every administrator, every user.. all at the same time? Say... right when everybody gets in in the morning. Something like that can easily cost a business tens of thousands of dollars.

It is effectively building a denial of service vulnerability into your password policies.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds