Comments

  • sik0fewl@piefed.ca
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 days ago

    “Security is theoretically worse since password lengths are exposed to people watching your screen, but this is an infinitesimal benefit far outweighed by the UX issue.”

    — SUDO-RS UPSTREAM COMMIT MESSAGE, ENABLING PWFEEDBACK BY DEFAULT

    Do people actually struggle with this, UX-wise? I find that I mistype my password just as often whether or not it is silent or asterisks.

    • TrickDacy@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      ·
      2 days ago

      I have many times accidentally pressed a single key and then had to start over because I had no feedback to confirm it’s only one accidental key press.

      • Martineski@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        8
        ·
        2 days ago

        I also hold the backspace for a (relatively) stupid long amount of time when I do know I made a typo because of no feedback on that either. Lol

        • rbos
          link
          fedilink
          English
          arrow-up
          5
          ·
          2 days ago

          Ctrl-U clears the line.

        • TrickDacy@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 days ago

          Yep. I either do that or Ctrl-C and run the command again. I think many of those will be avoidable with feedback

    • Flipper@feddit.org
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 days ago

      The first time i came across a sudo prompt i thought i didnt work. Yes. I think its bad for new comers.

      • sik0fewl@piefed.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        Ha. Didn’t even think of that. It definitely used to be a more common pattern.

  • apftwb@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 days ago

    If a malicious actor being able to see your terminal is part of your threat model, then remove pwfeedback from the sudoers file.

  • LouNeko@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    2 days ago

    I always thought this was a security feature. Guessing a password that you don’t know the length of is a lot harder.

    • TrickDacy@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      That is the reason for it. But I think people are finally admitting the scenarios where it actually helps security are exceedingly rare.