Path: utzoo!mnetor!uunet!husc6!cmcl2!brl-adm!brl-smoke!gwyn From: gwyn@brl-smoke.ARPA (Doug Gwyn ) Newsgroups: sci.crypt Subject: Re: Unix Password Cracker/Hacker Message-ID: <7329@brl-smoke.ARPA> Date: 23 Feb 88 22:30:15 GMT References: <772@ddsw1.UUCP> Reply-To: gwyn@brl.arpa (Doug Gwyn (VLD/VMB) ) Distribution: na Organization: Ballistic Research Lab (BRL), APG, MD. Lines: 10 In article <772@ddsw1.UUCP> dnelson@ddsw1.UUCP (Douglas Nelson) writes: >Also, I know it is available on most other operating systems, so perhaps it >is also available on Unix-type systems, a 'password expiration date' so to >say. This will force users to change thier passwords occasionally. This is a standard feature on UNIX System V (it is enabled on a per-account basis). But it's not really a good idea under normal circumstances -- if a person has chosen a good, secure password, it is folly to force them to change it. Eventually they will quit being careful and just pick a lousy password, affording an intruder an improved entry opportunity.