• [^] # Re: limiter les esssais ?

    Posté par . En réponse au journal La proche fin des mots de passe. Évalué à 3.

    D'ailleurs, c'est ce que fait Windows lors du login depuis au moins Windows 2000.

    Another reason why invalid passwords take longer to reject is to reduce the effectiveness of dictionary attacks. If invalid passwords were rejected just as quickly as valid passwords were accepted, then a bad guy could just churn through a dictionary trying out invalid passwords at high speed. Adding a delay of a few seconds before rejecting invalid passwords introduces a minor inconvenience to users who mistyped their passwords, but makes a huge dent in stopping dictionary attacks. For example (and these numbers are completely made up), suppose you have a 75,000 word password dictionary, and passwords are accepted or rejected in 100ms. It would take a little over three hours to attempt every password in the dictionary. Introducing even a simple 5-second delay into the rejection of invalid passwords increases the time to perform a dictionary search to over four days.

    Il y a aussi une règle (réglable dans gpedit.msc) qui permet de spécifier à partir de combien de tentatives foirées on bloque la machine, et pour combien de temps (typiquement, 30 minutes).

    "Quand certains râlent contre systemd, d'autres s'attaquent aux vrais problèmes." (merci Sinma !)