Bug#1064617: Passwords should not be changed frequently
Philip Hands <[email protected]> Tue, 05 Mar 2024 22:25:09 +0100
| Newsgroups | gmane.linux.debian.devel.bugs.general,gmane.linux.debian.internationalization.english |
|---|---|
| Message-ID | <[email protected]> |
--=-=-= Content-Type: text/plain Content-Transfer-Encoding: quoted-printable Justin B Rye <[email protected]> writes: > Holger Wansing wrote: >> @d-l10n-english: hey guys, we would like to get a proposal reviewed,=20 >> which aims to improve the root/user password screens in the installer. >>=20 >> Please find the related merge request at >> <https://salsa.debian.org/installer-team/user-setup/-/merge_requests/7> > > It needs a small amount of rephrasing, but the most important problem > is that it starts by saying you need to set a password and then goes > on to suggest that you might not need to set a password. Maybe that > can be fixed by rearranging things slightly... > > Template: passwd/root-password > Type: password > # :sl1: > _Description: Root password/passphrase: > To allow direct password/passphrase-based access to the 'root' > (system administrative) account you can set it up here. > The results can be disastrous if a malicious or incompetent user > obtains root access, so you should not set one that can be guessed, > found in dictionaries, or easily associated with you. > . > Alternatively, you can lock root's password > by leaving this setting empty, and > instead use the system's initial user account > (which will be set up in the next step) > to become root. This will be enabled for you > by adding that user to the 'sudo' group. > . > Note: what you type here will be hidden (unless you select to show it). > > Does this still feel like the same advice? The reason behind that structure was supposed to be that one definitely needs _a_ password, but not necessarily a root password, so the password advice applies to whichever password you'll decide to grant root access to, which might not be set here. I'm OK with the way you've phrased it, although my personal preference would be to simply drop the "disastrous" sentence if we use this version, because I think it breaks the straightforward flow of the text laying out the choice we're trying to get the user to make between the two available options. (I also rather doubt that anything we say at this point in the install will have the slightest influence on people's choice of password). > Otherwise the only thing I see is: > > Template: passwd/user-password > Type: password > # :sl1: > _Description: Choose a password/passphrase for the new user: > Make sure to select a strong password/passphrase, that cannot be guesse= d. > > No comma needed there. Well done -- I kept noticing that, and somehow didn't get round to fixing it. I've now deleted it, so thanks for pointing it out again. :-) Cheers, Phil. =2D-=20 Philip Hands -- https://hands.com/~phil --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3/FBWs4yJ/zyBwfW0EujoAEl1cAFAmXnjbYACgkQ0EujoAEl 1cAGjxAAxDn2nTqPHnoCFLS2hquOLmKqH104kyz4EXNgL2c5DPW5hlFpjqr3TOM6 vEpsg/Su11koQnNVVbGDZW6BoXPMD7H6mKTHMiiUX3vCniElyz7Kk/iA2f8oTsua hjJRLWZVQNIlR5wjyhCtcWsVBGLYVtQ4e0hDzbFFxPet8TYHIWibIn3OGExs1NrH kUNWy32Nqj7BYRK3saDMu69qJZ8JGy6KcOgEds6vj6LKjPD7Y1Uz6uauuW78Oq7E U6YwaWhHIuWq1CW45vF7pwj+NZ+oAl0gQ1KQe3AeMna1gsMBO34s7dAkhHKpSv6G XuUHOfN1QwQci0n3A+xmS83iPLRqD0KCe1KNqh353BPBgG5+qBQx5xqT152rnyvg wd8iBTEN36q0kpAMdkTJjKHR/XUbQKxUvAhndkmrpDjrD3fRtvXetWw96iRUjHFG FBBhdnH75tDb7loWdrviGYv/Gke7e/CebNRAW6C6VGtyKqenSfP6wRq21WI1ZaSK JkFuhzwWpzGvk7qaeM2DzEapzeLJk/CueoEnGwE9V/L2IF3iNSzx81jFrJ8PVUXE GRFqjwMQX9Ccr/F1qAOeZpU2BkQs8I8YUuQX/ErWmYn5x+pClyUwZpNGh7A14j/X kVKRd3egKPemxpIpTxK7O+9JePfUStJS5JRTODqeGHhkpq1YHlY= =ahO5 -----END PGP SIGNATURE----- --=-=-=--