12
submitted 10 months ago* (last edited 10 months ago) by penquin@lemmy.kde.social to c/kde@lemmy.kde.social

There is this useless feature where the lock screen tells you that the account is locked for 10 minutes because of three failed attempts to log in, but then I can just bypass it by forcing my computer off then powering it back on. Then what's the point of having it? I just got a new mechanical keyboard and I don't know if it has an issue or something, but it happened twice today without me doing anything while the pc is asleep, and it is annoying AF having to force shut down my pc by holding down the power button. This might also cause data loss for me. Is there a way to disable this thing?

Thanks

you are viewing a single comment's thread
view the rest of the comments
[-] Max_P@lemmy.max-p.me 6 points 10 months ago

That's managed by PAM: https://man.archlinux.org/man/faillock.8.en

I think it's mostly intended for remote access like when SSH'ing in, it locks up after too many bad attempts.

When you have physical access a lot of security stops being relevant. Although for users with full disk encryption, that'd also force the attacker to wipe the keys in RAM so it's still got some value.

[-] penquin@lemmy.kde.social 2 points 10 months ago* (last edited 10 months ago)

Ok, I figured it out. Looks like this new mechanical keyboard I got does something when I wake the PC up that causes those 3 attempts to be triggered. So I just set deny = 0 in /etc/security/faillock.conf. And to be more sure, I set the unlock time to 0. Lol That was very stressful. Thank you for bringing up faillock.

load more comments (2 replies)
this post was submitted on 20 Dec 2023
12 points (92.9% liked)

KDE

5207 readers
101 users here now

KDE is an international technology team creating user-friendly free and open source software for desktop and portable computing. KDE’s software runs on GNU/Linux, BSD and other operating systems, including Windows.

Plasma 6 Bugs

If you encounter a bug, proceed to https://bugs.kde.org, check whether it has been reported.

If it hasn't, report it yourself.

PLEASE THINK CAREFULLY BEFORE POSTING HERE.

Developers do not look for reports on social media, so they will not see it and all it does is clutter up the feed.

founded 1 year ago
MODERATORS