Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Password policy

Password policy

Scheduled Pinned Locked Moved Discuss
passwordfeature-request
9 Posts 4 Posters 1.8k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • yusfY Offline
    yusfY Offline
    yusf
    wrote on last edited by girish
    #1

    Inspired by reading the MSC2000 spec suggestion for Matrix, I want to suggest something similar for Cloudron. Have a look: https://github.com/matrix-org/matrix-doc/pull/2000

    1 Reply Last reply
    0
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #2

      We used to have strong password policies before and there were overwhelming number of mails to remove them 😕 And we did. We just stuck to 8 minimum length and since then nobody has complained.

      1 Reply Last reply
      1
      • mehdiM Offline
        mehdiM Offline
        mehdi
        App Dev
        wrote on last edited by
        #3

        I totally agree with the removal of such policies. Most studies have shown that the only good policy is length. Everything else makes passwords "hard for humans, easy for computers", which is bad.

        However, I think @yusf suggestion is to make them configurable by the admin. Some IT departments may have dumb policies they have to follow, and may need it

        1 Reply Last reply
        2
        • girishG Offline
          girishG Offline
          girish
          Staff
          wrote on last edited by
          #4

          I was also pointed to https://xkcd.com/936/ 🙂

          W 1 Reply Last reply
          4
          • girishG girish

            I was also pointed to https://xkcd.com/936/ 🙂

            W Offline
            W Offline
            will
            wrote on last edited by
            #5

            @girish @mehdi That comic is funny, but pretty horrible advice from a crypto perspective. Longer, more complex passwords are a better. That's why god invented password managers. 😊

            Here is a great thread that goes over both sides.
            https://www.reddit.com/r/technology/comments/1yxgqo/bruce_schneier_on_choosing_a_secure_password/cfovs83/

            And... apparently this is a thing:
            https://correcthorsebatterystaple.net

            mehdiM 1 Reply Last reply
            -1
            • W will

              @girish @mehdi That comic is funny, but pretty horrible advice from a crypto perspective. Longer, more complex passwords are a better. That's why god invented password managers. 😊

              Here is a great thread that goes over both sides.
              https://www.reddit.com/r/technology/comments/1yxgqo/bruce_schneier_on_choosing_a_secure_password/cfovs83/

              And... apparently this is a thing:
              https://correcthorsebatterystaple.net

              mehdiM Offline
              mehdiM Offline
              mehdi
              App Dev
              wrote on last edited by
              #6

              @will That comic is actually great advice 🙂

              Nobody is saying that longer and more complex aren't better as pure security. The point is that longer but less "complex" (as in less character classes, etc...), is much easier for humans, and much harder for computers, which (for passwords that a human must remember) is better.

              Of course, when you can use a password manager, and have passwords that are long AND complex, it's the best. But there's always at least the password-manager's password that you'll have to remember 🙂

              1 Reply Last reply
              0
              • W Offline
                W Offline
                will
                wrote on last edited by
                #7

                Using dictionary words, even seemingly random is really bad advice. One method my mom used was take lyrics to a favorite song, take the first letter of each word and use that for a password, mix up a little to your liking. Thats WAAAAAAAAAAAAAY more entropy than using a string of dictionary words.

                1 Reply Last reply
                0
                • yusfY Offline
                  yusfY Offline
                  yusf
                  wrote on last edited by
                  #8

                  Ah, you're probably right. I still want to be able to look for known leaked password, but that's for another topic.

                  W 1 Reply Last reply
                  0
                  • yusfY yusf

                    Ah, you're probably right. I still want to be able to look for known leaked password, but that's for another topic.

                    W Offline
                    W Offline
                    will
                    wrote on last edited by
                    #9

                    @yusf Bitwarden has that built in, I only found it the other day!

                    1 Reply Last reply
                    1
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                    • Login

                    • Don't have an account? Register

                    • Login or register to search.
                    • First post
                      Last post
                    0
                    • Categories
                    • Recent
                    • Tags
                    • Popular
                    • Bookmarks
                    • Search