Earlier quoted context omitted.
Unless they want to compromise you secretly.
Then spear Phishing is almost certainly more economical. Or just plugging a device into your laptop while you’re not looking and stealing all your session state for browsers.
Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
411–420 of 421 posts
Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#412Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#413Earlier quoted context omitted.
> Ubuntu became the most used because they were the first to really dumb down the install process. That is an urban myth relayed by people who weren't even using Ubuntu in its early days. Other distros were as easy to install as Ubuntu even before Ubuntu was founded. Besides Ubuntu was using the then experimental debian installer you could already use with a regular debian. They just shipped it on the default CD imag…
I'd largely forgotten about Mandrake/Mandriva, did they offer a live environment with installer as a GUI application? I'd tried to install Mandrake probably closer to the year 2000 and it certainly did not, but, there's a 4 year gap there that's a blind spot for me pre-Ubuntu. Never messed with Corel as it wasn't around long, so can't speak for that one. Focusing more on say, 2005ish, can you think of other examples?
Knoppix kind of led the way in 2000 so it is not surprising that Mandrake didn't have one yet but 5 years later it was already much more common. Some had separate isos for live or install though.
What Mandrake/Mandriva fell massively was in the branding department. All that mage related imagery made it look like a product for young kids and I am pretty sure that distro wasn't really taken seriously for this very reason.
Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#414Earlier quoted context omitted.
Knowing password length makes it easier to crack an insecure password. The SHA256 hash of a 6-symbol diceware password, where each symbol has its first letter capitalized and the rest lowercase, with 1! appended for compliance with misguided composition rules is 540b5417b5ecb522715fd4bb30f412912038900bd4ba949ea6130c8cb3c16012. There are 37 octets in the password. You know the length. You know the composition rules. Y…
Knowing that user passwords have to be manually keyed, I don’t think the average person will have a 37 character password set ;) Typically they’re between 8 and 12 characters. Usually contain dictionary terms, with the first character capitalised and a numeric value at the end with an exclamation mark. If you know a little bit of information about the individual (which you likely will if you’re in a position to shoul…
You also keep ignoring the fact that anyone who has access to see the length of your input in a shell has access to MUCH more useful information by watching/listening to you type.
Bottom line is that there is no realistic security loss from this, except for the most extreme contrived scenarios. While sure, this is not the best choice for 100% of users, it's still the best choice for 99.99999% of them, so it really doesn't bear discussion.
Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#415Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#416Earlier quoted context omitted.
The password, otherwise you have no way to check you've got it right.
Oh yeah, I can see why some might freak out about that.
Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#417Earlier quoted context omitted.
Knowing that user passwords have to be manually keyed, I don’t think the average person will have a 37 character password set ;) Typically they’re between 8 and 12 characters. Usually contain dictionary terms, with the first character capitalised and a numeric value at the end with an exclamation mark. If you know a little bit of information about the individual (which you likely will if you’re in a position to shoul…
You keep talking as if visible passwords is some scary never tried before thing. In reality, it's the almost universal norm, with Unixy terminal being the only place that does anything else. When you log into your UI (on Linux, Mac, and Windows), when you access your bank website, when you go to an ATM, when you log into your email account, and so many other places - all use a normal password input that echoes some c…
No. That’s you adding tone that wasn’t there.
> In reality, it's the almost universal norm, with Unixy terminal being the only place that does anything else. When you log into your UI (on Linux, Mac, and Windows), when you access your bank website, when you go to an ATM, when you log into your email account, and so many other places - all use a normal password input that echoes some character for every input.
Which is exactly why I talked about the audience of the security policies and not the technology ;)
It’s the risk appetite of the users that matter more here than the technology.
> You also keep ignoring the fact that anyone who has access to see the length of your input in a shell has access to MUCH more useful information by watching/listening to you type.
I didn’t ignore that. I just didn’t address it because there are a plethora of problems with key strokes and didn’t want to get drawn into a debate about that specifically. But since you asked:
1. They’re not always audible. Not everyone owns a mechanical keyboard ;)
2. backspace, ctrl+d and so on will be keystrokes that delete some or all of the password characters.
3. tab and enter are also keystrokes but also aren’t password characters
4. People are generally worse at counting sounds than counting sequences of visual clues
5. You might be watching someone on video rather than shoulder surfing so key sounds are unavailable
6. Other people might by typing in the vicinity and picking out one typist from another is exceptionally difficult vs reading dots on a screen
7. just because one thing exists it doesn’t automatically mean everything else has no value too
I could go on. But key sounds aren’t as big a giveaway as some on here would like to claim. And they’re definitely not on a par with dots on a screen.
However, if your security model is that even the key sounds are a risk then you / your organisation should be looking a passwordless systems like certificate-based logins.
So again, notice here that I’m not talking in absolute terms but instead discussing risks and their countermeasures.
> Bottom line is that there is no realistic security loss from this, except for the most extreme contrived scenarios. While sure, this is not the best choice for 100% of users, it's still the best choice for 99.99999% of them, so it really doesn't bear discussion.
Except you are discussing it and ended up making the same point I was but expressing it like a counter argument. It would have been a whole lot easier if you’d just said “I agree” but c'est la vie.
Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#418Earlier quoted context omitted.
I'd largely forgotten about Mandrake/Mandriva, did they offer a live environment with installer as a GUI application? I'd tried to install Mandrake probably closer to the year 2000 and it certainly did not, but, there's a 4 year gap there that's a blind spot for me pre-Ubuntu. Never messed with Corel as it wasn't around long, so can't speak for that one. Focusing more on say, 2005ish, can you think of other examples?
I think we'd have to dig old isos to check but livecds were all the rage in that era. Knoppix kind of led the way in 2000 so it is not surprising that Mandrake didn't have one yet but 5 years later it was already much more common. Some had separate isos for live or install though. What Mandrake/Mandriva fell massively was in the branding department. All that mage related imagery made it look like a product for young…
Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#419Re: Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
#420Earlier quoted context omitted.
I felt this pain yesterday. I use Open Core Legacy Patcher (OCLP) to run modern macOS on old Intel macs. The first time the computer boots after an upgrade (e.g. Sequoia 15.7.3 to 15.7.4), it is slow as a dog. Because the macOS upgrade clobbers all the OCLP driver patches. By "slow", I mean each keystroke on the login screen takes about 20-30 seconds for the corresponding bullet to appear in the password box. The log…
That's exactly the situation I wanted to avoid with our aging macbook. I knew it would be a hacky mess trying to keep beating that dead horse to get it to run the latest OS. We couldn't update some software that required us to be on the latest version of MacOS (Signal desktop), so the laptop became prematurely obsolete. We bought a Windows PC instead.