- Package:
- partman-crypto
- Source:
- partman-crypto
- Submitter:
- Jacek Wielemborek
- Date:
- 2013-10-01 17:03:04 UTC
- Severity:
- normal
Dear Maintainer, I noticed that the "choose password" dialog that can be seen when asked for a LUKS password in Debian Installer gives wrong advice on how a secure password looks like. It says that a good password contains both uppercase and lowercase characters and punctuation, which might mislead users that are unaware that 16-character password that is an impossible-to-remember mixture of characters is actually less secure than 20-characters-long password made of 4 English words, because the latter won't be so easily forgotten (and isn't that much easier to crack). Please change the text to educate the users properly on how to select passphrases (passphrases, not passwords).
Control: reassign -1 debian-installer
reassign 725009 partman-crypto
thanks
Quoting Andrei POPESCU (andreimpopescu@gmail.com):
The original bug report mentioned "LUKS password" which means the bug
report doesn't belong to user-setup but partman-crypto and is about
choosing the encryption passphrase.
A,nd, for what's is worth, I disagree with this bug report. People's
mileage may vary about what is good for a passphrase and what is
not. This is not the purpose of the installer to explain people how
secure pass{words|phrases} should be and how they should be to be
secure.
The point of the given details is about telling people what they can
do and what they can't.
So, I, for myself, veto any change to this debconf template.
2013/10/1 Christian PERRIER <bubulle@debian.org>: So, personally I believe that it would make sense to either state both of the approaches so that they could know how their mileage could actually vary or don't give any advice. The way it's put at the moment is quite confusing.