[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Admin/root password security hole



Jonas Pasche wrote:

> <bastard_operator_from_hell> we're thinking about a simple tool that tries
> to crack user passwords as a background process. the idea of e-mails like
> "hello. access to your account has been automatically disabled due to a too
> easy-to-guess password. please contact the technical support to get a new
> password." seems great to me. </bastard_operator_from_hell>

And how do you expect your customer to read the email if you've disabled
access <smile>?

> two reasons why we haven't installed it (yet):

See third reason above.

Jeff
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
nobaloney.net
P. O. Box 52672
Riverside, CA  92517
voice: (909) 787-8589  *  fax: (909) 782-0205