Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

"Been through Hell? Whaddya bring back for me?" -- A. Brilliant


dovenet / Synchronet Programming / src/sbbs3/useredit.cpp

SubjectAuthor
* src/sbbs3/useredit.cppRob Swindell (on ChromeOS)
`* src/sbbs3/useredit.cppMRO
 `* src/sbbs3/useredit.cppDigital Man
  `* src/sbbs3/useredit.cppMRO
   `* src/sbbs3/useredit.cppDigital Man
    +- src/sbbs3/useredit.cppMRO
    `* src/sbbs3/useredit.cppdeon
     +* src/sbbs3/useredit.cppDigital Man
     |+* src/sbbs3/useredit.cppdeon
     ||+* src/sbbs3/useredit.cppechicken
     |||`* src/sbbs3/useredit.cppMRO
     ||| +* src/sbbs3/useredit.cppechicken
     ||| |`- src/sbbs3/useredit.cppMRO
     ||| +* src/sbbs3/useredit.cppDigital Man
     ||| |`* src/sbbs3/useredit.cppMRO
     ||| | `* src/sbbs3/useredit.cppDigital Man
     ||| |  `* src/sbbs3/useredit.cppMRO
     ||| |   `- src/sbbs3/useredit.cppGamgee
     ||| `- src/sbbs3/useredit.cppTracker1
     ||+- src/sbbs3/useredit.cppDigital Man
     ||`* src/sbbs3/useredit.cppLmorchard
     || `- src/sbbs3/useredit.cppMRO
     |`- src/sbbs3/useredit.cppTracker1
     `* src/sbbs3/useredit.cppTracker1
      `* src/sbbs3/useredit.cppdeon
       `* src/sbbs3/useredit.cppDigital Man
        `* src/sbbs3/useredit.cppdeon
         `- src/sbbs3/useredit.cppDigital Man

Pages:12
src/sbbs3/useredit.cpp

<64041969.46719.syncprog@vert.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=720&group=DOVE-Net.Synchronet_Programming#720

  copy link   Newsgroups: DOVE-Net.Synchronet_Programming
From: digital.man@VERT (Digital Man)
To: deon
Subject: src/sbbs3/useredit.cpp
Message-ID: <64041969.46719.syncprog@vert.synchro.net>
Date: Sat, 4 Mar 2023 13:24:09 -0800
X-Comment-To: deon
Path: rocksolidbbs.com!not-for-mail
Organization: Vertrauen
Newsgroups: DOVE-Net.Synchronet_Programming
In-Reply-To: <64040F5B.8814.dove-syncprog@bbs.dege.au>
References: <64040F5B.8814.dove-syncprog@bbs.dege.au>
X-FTN-PID: Synchronet 3.20a-Linux master/5d1d586fd Mar 3 2023 GCC 12.2.0
X-FTN-MSGID: 46719.syncprog@1:103/705 286a05e8
X-FTN-REPLY: 8814.dove-syncprog@12:1/2 286967c9
X-FTN-CHRS: CP437 2
WhenImported: 20230304202409-0800 41e0
WhenExported: 20230304221813-0800 41e0
ExportedFrom: VERT syncprog 46719
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: Digital Man - Sat, 4 Mar 2023 21:24 UTC

Re: src/sbbs3/useredit.cpp
By: deon to Tracker1 on Sun Mar 05 2023 02:41 pm

> Re: src/sbbs3/useredit.cpp
> By: Tracker1 to deon on Sat Mar 04 2023 08:41 pm
>
> Howdy,
>
> > Because supported authentication mechanisms, such as CRAM-MD5 rely on
> > having the original (unencrypted) passphrase, or at least an intermediate
> > representation. Because of this, it would effectively need reversable
> > encryption... and because with SBBS this would most likely mean a key
> > that is right next to the vault... there's not much point in locking said
> > vault.
>
> Yeah, I hadnt considered the email authentication methods, like CRAM-MD5,
> that authenticated based on a known shared secret (the password), without
> transferring that over the wire. I believe that is the only other auth
> method that SBBS uses (over passwords in the clear).

There are several secure (non-plain text) authentication methods that Synchronet supports which assume the server has access to the user password in plain text, e.g. SSH password auth, HTTP digest auth, APOP, etc.

> But I dont agree with the last point "no much point locking said vault". I
> still think that having the passwords encrypted with a key is still better
> than having the password in the clear. But that might just be my view...

Not clear how/why that would be better. It would certainly give the impression of secure-password storage, but without the actual security. That sounds to me
"worse", not "better".
--
digital man (rob)

This Is Spinal Tap quote #11:
Nigel Tufnel: No. no. That's it, you've seen enough of that one.
Norco, CA WX: 47.3°F, 88.0% humidity, 3 mph SE wind, 0.01 inches rain/24hrs
---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net

src/sbbs3/useredit.cpp

<64046533.8816.dove-syncprog@bbs.dege.au>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=721&group=DOVE-Net.Synchronet_Programming#721

  copy link   Newsgroups: DOVE-Net.Synchronet_Programming
From: deon@VERT/ALTERANT (deon)
To: Digital Man
Subject: src/sbbs3/useredit.cpp
Message-ID: <64046533.8816.dove-syncprog@bbs.dege.au>
Date: Sun, 5 Mar 2023 13:47:31 +1100
X-Comment-To: Digital Man
Path: rocksolidbbs.com!not-for-mail
Organization: Alterant
Newsgroups: DOVE-Net.Synchronet_Programming
In-Reply-To: <64041969.46719.syncprog@vert.synchro.net>
References: <64041969.46719.syncprog@vert.synchro.net>
X-FTN-PID: Synchronet 3.19c-Linux custom/fb4e4ce96 Oct 27 2022 GCC 10.2.1
X-FTN-MSGID: 8816.dove-syncprog@12:1/2 2869bda3
X-FTN-REPLY: 46719.syncprog@1:103/705 286a05e8
X-FTN-CHRS: CP437 2
WhenImported: 20230305020940-0800 41e0
WhenExported: 20230305041815-0800 41e0
ExportedFrom: VERT syncprog 46720
WhenImported: 20230305204731+1100 9258
WhenExported: 20230305210943+1100 9258
ExportedFrom: ALTERANT dove-syncprog 8816
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: deon - Sun, 5 Mar 2023 02:47 UTC

Re: src/sbbs3/useredit.cpp
By: Digital Man to deon on Sat Mar 04 2023 08:24 pm

> Not clear how/why that would be better. It would certainly give the
> impression of secure-password storage, but without the actual security. That
> sounds to me "worse", not "better".

What was the motivation for unix developers to change /etc/passwd from having clear text passwords, to having DES crypt passwords? I'm sure at the time, folks didnt implement it becasue they thought it was "worse"?

> There are several secure (non-plain text) authentication methods that
> Synchronet supports which assume the server has access to the user password
> in plain text, e.g. SSH password auth, HTTP digest auth, APOP, etc.

Anyway, I get it - for challenge reponse mechanisms, SBBS doesnt have a "password database" for each type in use - prefering to having a single store for the user's password.

....δεσ∩

---
■ Synchronet ■ AnsiTEX bringing back videotex but with ANSI

src/sbbs3/useredit.cpp

<64047820.46721.syncprog@vert.synchro.net>

  copy mid

https://www.rocksolidbbs.com/dovenet/article-flat.php?id=722&group=DOVE-Net.Synchronet_Programming#722

  copy link   Newsgroups: DOVE-Net.Synchronet_Programming
From: digital.man@VERT (Digital Man)
To: deon
Subject: src/sbbs3/useredit.cpp
Message-ID: <64047820.46721.syncprog@vert.synchro.net>
Date: Sat, 4 Mar 2023 20:08:16 -0800
X-Comment-To: deon
Path: rocksolidbbs.com!not-for-mail
Organization: Vertrauen
Newsgroups: DOVE-Net.Synchronet_Programming
In-Reply-To: <64046533.8816.dove-syncprog@bbs.dege.au>
References: <64046533.8816.dove-syncprog@bbs.dege.au>
X-FTN-PID: Synchronet 3.20a-Linux master/5d1d586fd Mar 3 2023 GCC 12.2.0
X-FTN-MSGID: 46721.syncprog@1:103/705 286a64a1
X-FTN-REPLY: 8816.dove-syncprog@12:1/2 2869bda3
X-FTN-CHRS: CP437 2
WhenImported: 20230305030816-0800 41e0
WhenExported: 20230305041815-0800 41e0
ExportedFrom: VERT syncprog 46721
Content-Type: text/plain; charset=IBM437
Content-Transfer-Encoding: 8bit
 by: Digital Man - Sun, 5 Mar 2023 04:08 UTC

Re: src/sbbs3/useredit.cpp
By: deon to Digital Man on Sun Mar 05 2023 08:47 pm

> Re: src/sbbs3/useredit.cpp
> By: Digital Man to deon on Sat Mar 04 2023 08:24 pm
>
> > Not clear how/why that would be better. It would certainly give the
> > impression of secure-password storage, but without the actual security.
> > That sounds to me "worse", not "better".
>
> What was the motivation for unix developers to change /etc/passwd from
> having clear text passwords, to having DES crypt passwords? I'm sure at the
> time, folks didnt implement it becasue they thought it was "worse"?

Those passwords aren't reversable (able to be decrypted to the original clear text password) they're one-way hashes of a password. Not the same thing. A one-way hash of a password is more secure than storing the same password in either clear text or in a reversible form, but it also limits the subsequent uses of that stored hashed-password.
--
digital man (rob)

Sling Blade quote #5:
Karl Childers (to father): You ought not killed my little brother...
Norco, CA WX: 45.3°F, 87.0% humidity, 0 mph ENE wind, 0.01 inches rain/24hrs
---
■ Synchronet ■ Vertrauen ■ Home of Synchronet ■ [vert/cvs/bbs].synchro.net


dovenet / Synchronet Programming / src/sbbs3/useredit.cpp

Pages:12
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor