Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Password policy

Password policy

Scheduled Pinned Locked Moved Discuss
passwordfeature-request
11 Posts 6 Posters 3.0k Views 6 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • girishG Offline
    girishG Offline
    girish
    Staff
    wrote on last edited by
    #2

    We used to have strong password policies before and there were overwhelming number of mails to remove them 😕 And we did. We just stuck to 8 minimum length and since then nobody has complained.

    1 Reply Last reply
    1
    • mehdiM Offline
      mehdiM Offline
      mehdi
      App Dev
      wrote on last edited by
      #3

      I totally agree with the removal of such policies. Most studies have shown that the only good policy is length. Everything else makes passwords "hard for humans, easy for computers", which is bad.

      However, I think @yusf suggestion is to make them configurable by the admin. Some IT departments may have dumb policies they have to follow, and may need it

      1 Reply Last reply
      2
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #4

        I was also pointed to https://xkcd.com/936/ 🙂

        W 1 Reply Last reply
        4
        • girishG girish

          I was also pointed to https://xkcd.com/936/ 🙂

          W Offline
          W Offline
          will
          wrote on last edited by
          #5

          @girish @mehdi That comic is funny, but pretty horrible advice from a crypto perspective. Longer, more complex passwords are a better. That's why god invented password managers. 😊

          Here is a great thread that goes over both sides.
          https://www.reddit.com/r/technology/comments/1yxgqo/bruce_schneier_on_choosing_a_secure_password/cfovs83/

          And... apparently this is a thing:
          https://correcthorsebatterystaple.net

          mehdiM 1 Reply Last reply
          -1
          • W will

            @girish @mehdi That comic is funny, but pretty horrible advice from a crypto perspective. Longer, more complex passwords are a better. That's why god invented password managers. 😊

            Here is a great thread that goes over both sides.
            https://www.reddit.com/r/technology/comments/1yxgqo/bruce_schneier_on_choosing_a_secure_password/cfovs83/

            And... apparently this is a thing:
            https://correcthorsebatterystaple.net

            mehdiM Offline
            mehdiM Offline
            mehdi
            App Dev
            wrote on last edited by
            #6

            @will That comic is actually great advice 🙂

            Nobody is saying that longer and more complex aren't better as pure security. The point is that longer but less "complex" (as in less character classes, etc...), is much easier for humans, and much harder for computers, which (for passwords that a human must remember) is better.

            Of course, when you can use a password manager, and have passwords that are long AND complex, it's the best. But there's always at least the password-manager's password that you'll have to remember 🙂

            1 Reply Last reply
            0
            • W Offline
              W Offline
              will
              wrote on last edited by
              #7

              Using dictionary words, even seemingly random is really bad advice. One method my mom used was take lyrics to a favorite song, take the first letter of each word and use that for a password, mix up a little to your liking. Thats WAAAAAAAAAAAAAY more entropy than using a string of dictionary words.

              1 Reply Last reply
              0
              • yusfY Offline
                yusfY Offline
                yusf
                wrote on last edited by
                #8

                Ah, you're probably right. I still want to be able to look for known leaked password, but that's for another topic.

                W 1 Reply Last reply
                0
                • yusfY yusf

                  Ah, you're probably right. I still want to be able to look for known leaked password, but that's for another topic.

                  W Offline
                  W Offline
                  will
                  wrote on last edited by
                  #9

                  @yusf Bitwarden has that built in, I only found it the other day!

                  1 Reply Last reply
                  2
                  • C Offline
                    C Offline
                    charlesnw
                    wrote last edited by
                    #10

                    Would it be possible to allow the policy to be set period ? That way sites with higher security requirements can meet federal / enterprise standards ?

                    1 Reply Last reply
                    1
                    • J Offline
                      J Offline
                      joseph
                      Staff
                      wrote last edited by
                      #11

                      https://forum.cloudron.io/topic/13995/password-complexity is the feature request thread (which looks like you created, thanks)

                      1 Reply Last reply
                      0
                      • J joseph locked this topic
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search