libpam-smbpass is not "installed by default when you install samba". It is installed when you choose the "Samba file server" task in tasksel (which groups samba with other useful packages, when you don't know what to pick), or when you setup folder sharing in the desktop (where it makes sense as a default behavior). Both cases are targeted to novice users where enabling libpam-smbpass makes sense as the default.
I think that's a sane usability/discoverability/security trade-off. It's not installed when you install "samba" by itself, so it doesn't weaken security at all in most cases. You can safely remove it if you got it through the task or the folder sharing installer and prefer added security rather than that extra feature. ** Changed in: samba (Ubuntu) Status: Incomplete => Opinion -- libpam-smbpass syncs unix passwords when "unix password sync" is off https://bugs.launchpad.net/bugs/609092 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs