Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 14 Sep 2008 11:12:46 +0100 (BST)
From:      Robert Watson <rwatson@FreeBSD.org>
To:        mouss <mouss@netoyen.net>
Cc:        freebsd-security@freebsd.org, Khachatur Shahinyan <khachatur.shahinyan@arca.am>, Toby Burress <kurin@delete.org>
Subject:   Re: Freebsd auto locking users
Message-ID:  <alpine.BSF.1.10.0809141111230.72448@fledge.watson.org>
In-Reply-To: <48CC26A7.6020407@netoyen.net>
References:  <48CB52AE.6070501@arca.am> <20080913063522.GA3784@lithium.delete.org> <48CC26A7.6020407@netoyen.net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sat, 13 Sep 2008, mouss wrote:

>> A quick search doesn't show me any port for enforcing password age. For 
>> what it's worth, I once emailed Bruce Schneier about the effectiveness of 
>> that and he said he never changed his passwords (based on age, anyway). 
>> But there's probably something.
>
> Given that it's not easy to select a good password (both strong and easy to 
> remember), password expiration sometimes result in weak passwords or in 
> forgotten ones. or if no measure is taken against, people change to old 
> ones.
>
> http://www.cryptosmith.com/sanity/expharmful.html 
> http://www.rsa.com/blog/blog_entry.aspx?id=1286 
> http://www.cerias.purdue.edu/site/blog/post/password-change-myths/P50/
>
> and the other side has its proponents of course:
>
> http://lopsa.org/node/29

While these complaints about password expiration are certainly true, it seems 
like a common policy required by many sites, and failing to be able to support 
that policy will limit our ability to run at those sites.  It would be nice if 
we could complete the implementation of some of those password-related 
policies.

Robert N M Watson
Computer Laboratory
University of Cambridge



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?alpine.BSF.1.10.0809141111230.72448>