[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#364526: debian-installer: Please implement a password-checking module



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Christan:

Thanks for your response.
As you've quoted my comment was aimed a Debian in general. I have also
previously commended the d-i team on its improvement of the d-i in etch.
Much easier to use. In fact its now easier to use than MS's installer.
The GUI installer is very well done. Good job.

As long as the check is just a check and a warning then I have no
problem with it.

Unfortunately this was not the case with the local and time zone
settings (bug 448328). Just wanted to make sure the same thing didn't
happen here.

Again I think the d-i team has done an excellent job in improving the
d-i. Keep up the good work.

PS. I have an idea for doing Debian training. Can you point me in the
right direction. I don't want to go into details here as this is not the
right place for it. You can email me directly.


Thanks.


Christian Perrier wrote:
> Quoting Steven Demetrius (steven.demetrius@fiwwi.com):
> 
>> Many new users to Debian complain how difficult and geeky it is to use.
> 
> This is anything but a legend now. Sorry, but I (and probably many
> other D-I developers) feel sick when reading this as a full default
> Debian install is as painless as any other Linux system install. I
> suspect many Linux so-called gurus (or pseudo ones) to be responsible
> for this and continue to spread out such legend.
> 
> 
> Anyway, I think you'r emissing the point of the bug report.
> 
> Being able to use weak passwords is not something we plan to remove
> the possibility for. The point is only adding a check and warn users
> when they use weak passwords...giving them the opportunity to either
> go on, knowing what they're doing) or change their mind and use a
> stronger password.
> 
> Even in the closed-source software world, this is something that is
> done more and more (just look at the password policy for many
> corporate environments based on Microsoft products), so I don't think
> this is something that will scare users.
> 
> Again, this is not about strictly enforcing strong passwords.
> 
> Anyawy, all this is science-fiction right now as nobody cared enough
> to implement a good password quality test in user-setup.
> 
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHJGlVE5pZTZCwxmQRAjNyAJ42rImDsJl8p40v42YrG0cwFLdSfgCfX5bG
bSTZbpm30BrbD9ymePgRkdk=
=Z+bV
-----END PGP SIGNATURE-----




Reply to: