Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Password policy

Password policy

Scheduled Pinned Locked Moved Discuss
passwordfeature-request
9 Posts 4 Posters 1.5k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • yusfY Offline
      yusfY Offline
      yusf
      wrote on last edited by girish
      #1

      Inspired by reading the MSC2000 spec suggestion for Matrix, I want to suggest something similar for Cloudron. Have a look: https://github.com/matrix-org/matrix-doc/pull/2000

      1 Reply Last reply
      0
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #2

        We used to have strong password policies before and there were overwhelming number of mails to remove them 😕 And we did. We just stuck to 8 minimum length and since then nobody has complained.

        1 Reply Last reply
        1
        • mehdiM Offline
          mehdiM Offline
          mehdi
          App Dev
          wrote on last edited by
          #3

          I totally agree with the removal of such policies. Most studies have shown that the only good policy is length. Everything else makes passwords "hard for humans, easy for computers", which is bad.

          However, I think @yusf suggestion is to make them configurable by the admin. Some IT departments may have dumb policies they have to follow, and may need it

          1 Reply Last reply
          2
          • girishG Offline
            girishG Offline
            girish
            Staff
            wrote on last edited by
            #4

            I was also pointed to https://xkcd.com/936/ 🙂

            W 1 Reply Last reply
            4
            • girishG girish

              I was also pointed to https://xkcd.com/936/ 🙂

              W Offline
              W Offline
              will
              wrote on last edited by
              #5

              @girish @mehdi That comic is funny, but pretty horrible advice from a crypto perspective. Longer, more complex passwords are a better. That's why god invented password managers. 😊

              Here is a great thread that goes over both sides.
              https://www.reddit.com/r/technology/comments/1yxgqo/bruce_schneier_on_choosing_a_secure_password/cfovs83/

              And... apparently this is a thing:
              https://correcthorsebatterystaple.net

              mehdiM 1 Reply Last reply
              -1
              • W will

                @girish @mehdi That comic is funny, but pretty horrible advice from a crypto perspective. Longer, more complex passwords are a better. That's why god invented password managers. 😊

                Here is a great thread that goes over both sides.
                https://www.reddit.com/r/technology/comments/1yxgqo/bruce_schneier_on_choosing_a_secure_password/cfovs83/

                And... apparently this is a thing:
                https://correcthorsebatterystaple.net

                mehdiM Offline
                mehdiM Offline
                mehdi
                App Dev
                wrote on last edited by
                #6

                @will That comic is actually great advice 🙂

                Nobody is saying that longer and more complex aren't better as pure security. The point is that longer but less "complex" (as in less character classes, etc...), is much easier for humans, and much harder for computers, which (for passwords that a human must remember) is better.

                Of course, when you can use a password manager, and have passwords that are long AND complex, it's the best. But there's always at least the password-manager's password that you'll have to remember 🙂

                1 Reply Last reply
                0
                • W Offline
                  W Offline
                  will
                  wrote on last edited by
                  #7

                  Using dictionary words, even seemingly random is really bad advice. One method my mom used was take lyrics to a favorite song, take the first letter of each word and use that for a password, mix up a little to your liking. Thats WAAAAAAAAAAAAAY more entropy than using a string of dictionary words.

                  1 Reply Last reply
                  0
                  • yusfY Offline
                    yusfY Offline
                    yusf
                    wrote on last edited by
                    #8

                    Ah, you're probably right. I still want to be able to look for known leaked password, but that's for another topic.

                    W 1 Reply Last reply
                    0
                    • yusfY yusf

                      Ah, you're probably right. I still want to be able to look for known leaked password, but that's for another topic.

                      W Offline
                      W Offline
                      will
                      wrote on last edited by
                      #9

                      @yusf Bitwarden has that built in, I only found it the other day!

                      1 Reply Last reply
                      1
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • Bookmarks
                        • Search