logoalt Hacker News

timhhyesterday at 7:47 AM1 replyview on HN

Not for local password authentication.

https://github.com/pibara/pam_unix/blob/master/unix_chkpwd.c...


Replies

onraglanroadyesterday at 12:36 PM

Yes, for local password authentication.

The code you linked to isn't the code for a wrong password. It's a check to make sure you're using a TTY. That code isn't to prevent brute force. The delay there is 10 seconds.

The 2 second delay is in support.c at https://github.com/pibara/pam_unix/blob/5727103caa9404f03ef0...

It only runs if "nodelay" is not set. But you might have another pam module setting its own delay. I have pam_faildelay.so set in /etc/pam.d/login

Change both the config files and you can remove the delay if you want.

show 1 reply