[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#656509: marked as done (user-setup-udeb: Please consider amending password advice)



Your message dated Sun, 2 Mar 2014 16:22:38 +0100
with message-id <20140302152238.GA14895@mraw.org>
and subject line Re: Bug#656509: user-setup-udeb: Please consider amending password advice
has caused the Debian Bug report #656509,
regarding user-setup-udeb: Please consider amending password advice
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
656509: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=656509
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: user-setup-udeb
Severity: wishlist


d-i says:

   A good password will contain a mixture of letters, numbers and
   punctuation and should be changed at regular intervals.

Complexity in a password is good and probably unarguable, although
length should also be considered to have some importance, Why advise
changing it at regular intervals? Why not advocate not imparting it to
anyone or not reusing it on other systems? Is there something which
causes a good password to degenerate over time?

The second part of the advice does not appear to have any technical
basis so removing it would be of little consequence.



--- End Message ---
--- Begin Message ---
Christian PERRIER <bubulle@debian.org> (2012-01-20):
> Quoting Brian Potkin (claremont102@gmail.com):
> > d-i says:
> > 
> >    A good password will contain a mixture of letters, numbers and
> >    punctuation and should be changed at regular intervals.
> > 
> > Complexity in a password is good and probably unarguable, although
> > length should also be considered to have some importance, Why advise
> > changing it at regular intervals? Why not advocate not imparting it to
> > anyone or not reusing it on other systems? Is there something which
> > causes a good password to degenerate over time?
> > 
> > The second part of the advice does not appear to have any technical
> > basis so removing it would be of little consequence.

It takes a few seconds to find something like this in a search engine:
  https://www.schneier.com/blog/archives/2010/11/changing_passwo.html

> Are you ready to handle the round of updates for over sixty languages,
> for a very debatable and cosmetic change?
> 
> I am not, sorry.

Neither am I, so I'll just close this bug report for now.

Mraw,
KiBi.

Attachment: signature.asc
Description: Digital signature


--- End Message ---

Reply to: