[colug-432] su broken on ...

Thomas W. cranston cranston.thomas at gmail.com
Mon Feb 21 10:19:03 EST 2011


On 02/21/2011 05:34 AM, Scott Merrill wrote:
> On Mon, Feb 21, 2011 at 1:04 AM, Vincent Herried<vince at planetvince.info>  wrote:
>    
>> No ideas on why the gue for users shows fewer characters than
>> the password?  hmmm wondering... much of this work was
>> done from host lap3.vince  ssh desk.vince
>> nah makes no sense why that would mess it up
>>      
> My guess is that there's no useful reason to show the correct number
> of characters in a password when you're changing that password: if you
> know the password, you can change it successfully, and if you don't
> know the password then seeing the correct number of characters will
> help you deduce a poorly chosen password, or more quickly brute force
> it.
>
>    
Point well taken, but usually the way thinks work is that you get the 
correct number of characters as your password (or none at all)

Getting a different number of characters is probably a symptom of 
something wrong.
> _______________________________________________
> colug-432 mailing list
> colug-432 at colug.net
> http://lists.colug.net/mailman/listinfo/colug-432
>    
Tom


More information about the colug-432 mailing list