Results 1 to 6 of 6

Thread: Why does confirmation of wrong password takes so long time?

  1. #1
    Join Date
    Mar 2009
    Location
    Riga, Latvia
    Beans
    55
    Distro
    Ubuntu Studio 10.10 Maverick Meerkat

    Question Why does confirmation of wrong password takes so long time?

    I am just wondering, why is it so that when you enter a wrong password at the login screen it takes about 2 seconds for Ubuntu to answer that the password is incorrect? When you enter the password correctly, Ubuntu understands it in less than 0,1 sec and your'e welcome to your desktop.
    I am sure that Ubuntu understands that password is incorrect as fast as it understands that the password is correct. How it would be possible to change the time Ubuntu "checks" wrongly inputed password?
    I hope my thought is clear and you understand me.
    Have a nice day!
    Thank you!

  2. #2
    Join Date
    Nov 2009
    Location
    Los Angeles
    Beans
    393
    Distro
    Ubuntu

    Re: Why does confirmation of wrong password takes so long time?

    There may be a lot of things contributing to that, but I'll bet at least half a second or more is purely an arbitrary wait to thwart brute-force attacks. You'll see a similar wait period in many registration windows for proprietary software. Even a modest half-second wait can turn a brute-force crack that might have taken hours into one that can take weeks.

  3. #3
    Join Date
    Feb 2009
    Location
    USA
    Beans
    3,186

    Re: Why does confirmation of wrong password takes so long time?

    If your machine is fast enough, I can hit it with hundreds if not thousands of passwords per second. It may not be to long before I hit the right one. Making me wait a second before attempts, prevents such an attack.

  4. #4
    Join Date
    Mar 2009
    Location
    Riga, Latvia
    Beans
    55
    Distro
    Ubuntu Studio 10.10 Maverick Meerkat

    Re: Why does confirmation of wrong password takes so long time?

    Thank you for your explanation! Didn't think about that from that point of view! Now it's clear.
    Thank you rg4w and 3Miro!

  5. #5
    hakermania's Avatar
    hakermania is offline Τώρα ξέρεις τι γράφω εδώ!
    Join Date
    Aug 2009
    Location
    Greece
    Beans
    1,705
    Distro
    Ubuntu Development Release

    Re: Why does confirmation of wrong password takes so long time?

    I had the same question once and yes, this is the answer....
    but it is annoying, isn't it?
    sudo could log the sudo attempts and if there are 3 wrong attempts, so to understand that probably something goes wrong and for 5 minutes it could have the delay and then again without the delay and if 3 wrong attempts again 5 minutes the delay and so on, it's no use having the delay always...

  6. #6
    Join Date
    Dec 2009
    Location
    germany
    Beans
    1,020
    Distro
    Ubuntu 12.04 Precise Pangolin

    Re: Why does confirmation of wrong password takes so long time?

    Quote Originally Posted by Svens View Post
    I am just wondering, why is it so that when you enter a wrong password at the login screen it takes about 2 seconds for Ubuntu to answer that the password is incorrect? When you enter the password correctly, Ubuntu understands it in less than 0,1 sec and your'e welcome to your desktop.
    I am sure that Ubuntu understands that password is incorrect as fast as it understands that the password is correct. How it would be possible to change the time Ubuntu "checks" wrongly inputed password?
    I hope my thought is clear and you understand me.
    Have a nice day!
    Thank you!
    hello

    normaly there is a resolution for your problem - but not in ubuntu ( i tried it, even after i changed the file
    /etc/login.defs).
    there is a option called: FAIL_DELAY=nn-seconds
    but it don't works on my system (10.10). it works on suse.
    may be there are a couple of files to change. but the only way to change it on different other systems was
    to change this option.
    but in mind - other people told you --> even if it possible --> don't decrease that limit --> if there is a way
    to set it higher --> that's ok.
    ciao
    "What is the robbing of a bank compared to the FOUNDING of a bank?" Berthold Brecht

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •