[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Release-critical Bugreport for June 23, 2000



ressu@uusikaupunki.fi (Sami Haahtinen) writes:

> [1  <text/plain; us-ascii (quoted-printable)>]
> On Fri, Jun 23, 2000 at 12:53:48PM +0200, Wichert Akkerman wrote:
> > > > Package: pwgen (debian/main)
> > > > Maintainer: Vincent Renardias <vincent@debian.org>
> > > >   66006  pwgen: pwgen uses 'oo' letters in generated passwords too frequently
> > > 
> > > heh
> > 
> > Is that really true?
> 
> Confirmed...
> 
> ressu@ressukka:~$ pwgen 10 100000|grep oo|wc -l
>   50885

Even more scary is

% pwgen 8 100000 | sort | uniq -c | sort -nr | head
     17 thoothi
     17 thithoo
     13 thooqui

I think should be possible to generate 100000 passwords without
repeating some 17 times. ("thoothi" and "thithoo" seem to win all the
time...)

Regarding there's also an open bug about a missing license, which IMHO
alone makes this unsuitable for release, I would really consider
flagging this package for removal.

	Falk



Reply to: