Menu

#112 Finish support for passwords up to 32 characters in length

MCRB
closed
MCRB (7)
2017-02-11
2017-01-04
No

While the PNT software appears to support passwords greater than 8 characters in length, passwords are currently limited to 8 characters -- probably because the answering service doesn't support passwords greater than this length. In this day and age, limiting passwords to 8 characters provides laughable security. Since 32-character passwords appear to be supported at the PNT level, we should investigate what it would take to enable passwords of up to 32 characters.

Discussion

  • Rick Kissel

    Rick Kissel - 2017-01-04

    Given the historical silliness of some password rules, here's some recent articles on good passwords and what we're protecting against:

    https://www.ece.cmu.edu/~lbauer/papers/2016/tissec2016-password-policies.pdf
    http://cacm.acm.org/magazines/2015/7/188731-passwords-and-the-evolution-of-imperfect-authentication/abstract
    http://cacm.acm.org/magazines/2016/11/209115-pushing-on-string/abstract
    https://www.microsoft.com/en-us/research/publication/an-administrators-guide-to-internet-password-research/
    

    The last one is a paper on which the CACM one was based (I think) so it has some more details.

     
  • Eric Swenson

    Eric Swenson - 2017-02-11

    Closing as ticket moved here: http://multics-trac.swenson.org/ticket/35

     
  • Eric Swenson

    Eric Swenson - 2017-02-11
    • status: open --> closed
     
  • Eric Swenson

    Eric Swenson - 2017-02-11
    • Milestone: 1.0 --> MCRB
     

Log in to post a comment.

MongoDB Logo MongoDB