| Summary: | Lockscreen: don't time block password entry - only login attempts. | ||
|---|---|---|---|
| Product: | [Unmaintained] kscreenlocker | Reporter: | Pascal d'Hermilly <pascal> |
| Component: | greeter | Assignee: | Plasma Bugs List <plasma-bugs-null> |
| Status: | RESOLVED INTENTIONAL | ||
| Severity: | wishlist | CC: | bshah, mgraesslin |
| Priority: | NOR | ||
| Version First Reported In: | unspecified | ||
| Target Milestone: | --- | ||
| Platform: | Other | ||
| OS: | Linux | ||
| Latest Commit: | Version Fixed/Implemented In: | ||
| Sentry Crash Report: | |||
|
Description
Pascal d'Hermilly
2017-10-11 15:31:31 UTC
This is just another case of the old: security vs. comfort. The password field is disabled for increased security to make it more annoying to brute force the password. Right. But could it wait with the annoying part until after 3 failed attempts? 3 attempts isn't exactly "brute force". (In reply to Pascal d'Hermilly from comment #2) > Right. But could it wait with the annoying part until after 3 failed > attempts? > 3 attempts isn't exactly "brute force". Erm no, that's just too complicated to track and get right. This is security related code, better safe than sorry. ok. Thanks for listening :-) |