Re: Freebsd auto locking users
- From: Robert Watson <rwatson@xxxxxxxxxxx>
- Date: Sun, 14 Sep 2008 11:12:46 +0100 (BST)
On Sat, 13 Sep 2008, mouss wrote:
A quick search doesn't show me any port for enforcing password age. For what it's worth, I once emailed Bruce Schneier about the effectiveness of that and he said he never changed his passwords (based on age, anyway). But there's probably something.
Given that it's not easy to select a good password (both strong and easy to remember), password expiration sometimes result in weak passwords or in forgotten ones. or if no measure is taken against, people change to old ones.
http://www.cryptosmith.com/sanity/expharmful.html http://www.rsa.com/blog/blog_entry.aspx?id=1286 http://www.cerias.purdue.edu/site/blog/post/password-change-myths/P50/
and the other side has its proponents of course:
http://lopsa.org/node/29
While these complaints about password expiration are certainly true, it seems like a common policy required by many sites, and failing to be able to support that policy will limit our ability to run at those sites. It would be nice if we could complete the implementation of some of those password-related policies.
Robert N M Watson
Computer Laboratory
University of Cambridge
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: Freebsd auto locking users
- From: mouss
- Re: Freebsd auto locking users (minor correction
- From: Micheas Herman
- Re: Freebsd auto locking users
- References:
- Freebsd auto locking users
- From: Khachatur Shahinyan
- Re: Freebsd auto locking users
- From: Toby Burress
- Re: Freebsd auto locking users
- From: mouss
- Freebsd auto locking users
- Prev by Date: Re: Freebsd auto locking users
- Next by Date: Re: Freebsd auto locking users (minor correction
- Previous by thread: Re: Freebsd auto locking users
- Next by thread: Re: Freebsd auto locking users (minor correction
- Index(es):