Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 28 May 2013 05:47:09 +0400
From: Solar Designer <solar@...nwall.com>
To: Michael Samuel <mik@...net.net>
Cc: oss-security@...ts.openwall.com
Subject: Re: CVE Request: pwgen

On Tue, May 28, 2013 at 01:33:48AM +0000, Michael Samuel wrote:
> The default mode of this program generates extremely low entropy passwords - 
> It is probably worth changing the default to "secure" mode and removing 
> phonemes mode, to avoid putting users at risk.

Yes.  You have seen the thread on pwgen from last year, right? -

http://www.openwall.com/lists/oss-security/2012/01/22/6

(Use the "thread-prev" link for more messages from that thread.)

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.