vnc security glitch: long passwords

Jonathan Morton chromatix "at"
Mon, 07 Aug 2000 10:41:49 +0000

> VNC doesn't complain if you try to assign a password
>longer than it actually uses.  The security problem is
>that if you habitually use such long passwords, you may
>think you're giving each host a different password, but
>you're not.  The hazard is obvious.

The VNC Server which I am writing (practically from scratch) uses an
8-character-limited entry box for the password, which bleeps if you try to
enter more than that.  If the protocol is developed in the future to allow
longer passwords, this restriction can be removed.

