automatically generated password too complicated?
data:image/s3,"s3://crabby-images/d12b9/d12b943dcbce8203c88d23465381c34c503910a7" alt=""
Some of our users complained about the automatically generated
passwords that are sent out when a list is imported or if an admin
subscribes someone. Especially the and ^ characters are major problem because these may be treated as parts of composite characters in some enviroments (
followed by a might be displayed as the same
character as à in HTML) and so on. Also, upper case characters
impose an extra mental burden ;)
Anyway, I modified our Mailman which now has a function (method?) Utils.GetRandomPassword(length)
which generates passwords of the given length with a restricted alphabet, namely: a-x, 2-9, excluding characters o and l as well as digits 0 and 1 which may be confused and y, z (german keyboards swap these, in the past, this cause trouble too ;)
I would like to offer this patch unless there are good reasons why this should be avoided. The main concern is certainly a higher risk to crack such passwords (only 30 possibilities instead of 64) but this could easly be matched by using 5 character passwords:
possibilities strength
64^4 = 16777216 1 30^4 = 810000 0.05 30^5 = 24300000 1.45
As far as I have seen, this patch involves replacing certain calls to GetRandomSeed in a few places such as: bin/add_members, Mailman/Cgi/admin.py, Mailman/MailCommandHandler.py
Any comment?
+gg
-- Gerhard.Gonter@wu-wien.ac.at Fax: +43/1/31336/702 g.gonter@ieee.org Zentrum fuer Informatikdienste, Wirtschaftsuniversitaet Wien, Austria
data:image/s3,"s3://crabby-images/d12b9/d12b943dcbce8203c88d23465381c34c503910a7" alt=""
Huh? Did that posting hide in a mail queue for 2.5 months??
+gg
-- Gerhard.Gonter@wu-wien.ac.at Fax: +43/1/31336/702 g.gonter@ieee.org Zentrum fuer Informatikdienste, Wirtschaftsuniversitaet Wien, Austria --- Linux or FreeBSD, it's like blondes or brunettes. I like both. --
data:image/s3,"s3://crabby-images/af2b6/af2b602899423847390a0eeebd6d37890816073a" alt=""
On Tue, 20 Apr 1999, Gerhard Gonter wrote:
Hm... I've long been using a replacement for the standard random
password generator that greates three word phrases separated by dashes (such as 'wise-red-fox') The words are randomly picked from a list for each position. with about 20-50 words in each list there's abt 100 thousand combos. If the list of words are picked right, the password phrases 'sort of' make sense, and thus are easy to remember.
(the caveat being the fact that since the phrases are words there is a language issue... Whatever)
-The Dragon De Monsyne
data:image/s3,"s3://crabby-images/d12b9/d12b943dcbce8203c88d23465381c34c503910a7" alt=""
Huh? Did that posting hide in a mail queue for 2.5 months??
+gg
-- Gerhard.Gonter@wu-wien.ac.at Fax: +43/1/31336/702 g.gonter@ieee.org Zentrum fuer Informatikdienste, Wirtschaftsuniversitaet Wien, Austria --- Linux or FreeBSD, it's like blondes or brunettes. I like both. --
data:image/s3,"s3://crabby-images/af2b6/af2b602899423847390a0eeebd6d37890816073a" alt=""
On Tue, 20 Apr 1999, Gerhard Gonter wrote:
Hm... I've long been using a replacement for the standard random
password generator that greates three word phrases separated by dashes (such as 'wise-red-fox') The words are randomly picked from a list for each position. with about 20-50 words in each list there's abt 100 thousand combos. If the list of words are picked right, the password phrases 'sort of' make sense, and thus are easy to remember.
(the caveat being the fact that since the phrases are words there is a language issue... Whatever)
-The Dragon De Monsyne
participants (3)
-
Barry A. Warsaw
-
Gerhard Gonter
-
The Dragon De Monsyne