4 ms·
I also think it is a good decision. Nevertheless it breaks the workflow of at least one person. My father's Linux password is one character. I didn't knew this
by ahofmann 7mo ago
I also think it is a good decision.
Nevertheless it breaks the workflow of at least one person. My father's Linux password is one character. I didn't knew this when I supported him over screen sharing methods, because I couldn't see it. He told me, so now I know. But the silent prompt protected that fact.
It is still a good decision, an one character password is useless from a security standpoint.
- zx8080 7mo ago> It is still a good decision, an one character password is useless from a security standpoint. Only if length is known. Which is true now. So it opens the gates to try passwords of specific known length.
- ludston 7mo agoIf you are brute forcing passwords, knowing the length only reduces the number of passwords to try by like 1 hundredth.
- egeres 7mo agoIt also give you the possibility of filtering out which ones are worth cracking and which ones not
- elcritch 7mo agoIt could also give useful priors for targeted attacks, "Their password is 5 characters, and their daughters name is also 5 characters, let's try variations of that".
- justsomehnguy 7mo agoSome system accessible to hackers who can see the length of the password /and/ having a single 5 char password has a security of a key under a doormat.
- egeres 7mo agoMaybe this is far fetched, but you could get an LLM-based auto-research system to extract these potential relationships
- elcritch 7mo agoDrats, you're right. I thought it'd be worse, but the ratio seems to only depend on the number of letters in your character set: 1/count(letters in alphabet). For ascii at 95 printable chars you get 0.9894736842. Makes intuitive sense as the "weight" of each digit increases, taking away a digit matters less to the total combos. Maybe I'll start using one Japanese Kanji to confuse would be hackers! They could spend hours trying to brute force it while wondering why they can't crack my one letter password they saw in my terminal prompt. ;)
- Obscurity4340 7mo agoIts funny how a single japanese symbol would be harder to crack than the anglicized name for it
- LoganDark 7mo agoDo we know if the asterisks count Unicode code points rather than bytes?
- Izkata 7mo agoDoesn't really matter, the IME shows the input until you confirm which kanji you want.
- LoganDark 7mo agoWhen the IME inserts the character, it'll be made up of multiple bytes because of the nature of UTF-8, so it may appear as multiple asterisks regardless.
- necovek 7mo agoMost software, traditional sudo included, would respect the LC_CTYPE being set to an UTF-8 (or any of the older multi-byte encodings), and do proper character counting. At the very least, all GNU tools put a lot of focus on localization support, and I hope sudo-rs is the same.
- brnt 7mo agoI may or may not use a single char password on a certain machine. This char may or may not be a single space. It may or may not be used in FDE. It's surprising what (OS installers) this breaks.
- airstrike 7mo agoIf it breaks the workflow of one person but makes it better for many more, it's likely a worthwhile tradeoff.
- dietr1ch 7mo agoJust add an option to let holding space keep my feet warm. It only needs a few extra lines that won't change.
- wartywhoa23 7mo agoHow much would unknown password length protect against bruteforcing a 1 character password?
- nextlevelwizard 7mo agoThis has always been an option and your dad can just flip the default back to not show it