The user account password requirements should be less strict

Bug #821765 reported by Dylan McCall
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
gnome-control-center
Invalid
Undecided
Unassigned
gnome-control-center (Ubuntu)
Confirmed
Wishlist
Unassigned

Bug Description

The password field in the User Accounts panel enforces corporatey password requirements. Passwords must be a particular length, must not be "too simple", and cannot be similar to existing passwords. Consider a case where a user accidentally enters a password with caps lock turned on. There will be no way to solve this without choosing a different password altogether. Also because of this requirement, one cannot change a hint for an existing password.

Ubuntu aims to be an easy to use operating system at home - one that doesn't demand too much from the user. So, this feature should probably be turned off in our case.

Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug report, pitti do you have any opinion on that? I don't really have a strong one either way but I found it somewhat annoying as well while doing install testing there ;-)

Changed in gnome-control-center (Ubuntu):
importance: Undecided → Wishlist
status: New → Confirmed
summary: - Password changing is needlessly abusive
+ The user account password requirements should be less strict
Changed in gnome-control-center:
status: New → Incomplete
Revision history for this message
Sebastien Bacher (seb128) wrote :

let's maybe not forward it upstream for now

Changed in gnome-control-center:
status: Incomplete → Invalid
Revision history for this message
Dylan McCall (dylanmccall) wrote :

Thanks :)

Oh, some ways to reproduce this:

Try changing to the password “aaaaa1.” You will be told that the password is too simple. (Interestingly, this doesn't happen with “password,” perhaps because it exceeds the length requirement).

Try to enter a new password that contains a subset of your current password. For example, if your password is “password,” change to “passw1.” You will be told that the passwords are too similar.

Revision history for this message
Martin Pitt (pitti) wrote :

I wouldn't mind if control-center dropped its own checks and leaves the strength checking to PAM. There is already cracklib and other PAM plugins which check password quality for all interfaces (not just control-center).

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.