PenUltima Online Forum Index Official Core: 096.7
Official Core: 097 2008-02-26
Donate towards the POL web hosting bill!
 POL Home   FAQ   Search    Memberlist   Usergroups    Register    Profile   Log in to check your private messages   Log in
"GetPassword"

 
Post new topic   Reply to topic    PenUltima Online Forum Index -> Feature Suggestions
Display posts from previous:   

Author Message
*Edwards



Joined: 29 Dec 2007
Posts: 85
Location: Montreal, Canada

PostPosted: Thu Feb 21, 2008 11:54 pm    Post subject: "GetPassword" Reply with quote

Well I gave the opportunity to my higher staff to see the account informations using a command but it is impossible with pol to "getpassword" and display it. Would be great if it could be added in the futur..

Author Message
OldnGrey



Joined: 04 Feb 2006
Posts: 520

PostPosted: Fri Feb 22, 2008 3:06 am    Post subject: Reply with quote

I personally would like the password to be impossible to retrieve.

As a security administrator it's a key part of password management to make them unreadable due to encryption so all we can do is set a password for the user.

Of course pol allows you to have cleartext or md5 encrypted passwords stored in the accounts.txt file, but I really dislike this feature. I much prefer players to have the security of knowing their password cannot be read by anyone, me included.

Author Message
*Edwards



Joined: 29 Dec 2007
Posts: 85
Location: Montreal, Canada

PostPosted: Fri Feb 22, 2008 3:41 am    Post subject: Reply with quote

Just addind the possibility for... would simply give an opportunity to use it or not.

We are 3 friends running a shard together since 1 year and I can trust them at 100%. Plus our server seems well secured. That could be an option in pol.cfg or something... A lot of oldies would like to start fast and I would gave the opportunity to my friends to read a password through a command. Few would say it is not safe at all Edwards! but considering the fact that only specific ips are now allowed to use a staff member and in addition a secret code for using the command... it makes it safer... I still really care about the hard work spent by our players on our lands

Author Message
Pierce



Joined: 02 Feb 2006
Posts: 256

PostPosted: Fri Feb 22, 2008 6:07 pm    Post subject: Reply with quote

OldnGrey wrote:

I personally would like the password to be impossible to retrieve


I couldn't state that better. I am strongly against such a command.
You can give your trusted staff members the command to change the current password but why should they read the old one? If someone forgets his password he needs to be send his old or new one. So you can simply give a new one via email. A command to read it is always a possible security leak.

Author Message
*Edwards



Joined: 29 Dec 2007
Posts: 85
Location: Montreal, Canada

PostPosted: Fri Feb 22, 2008 8:36 pm    Post subject: Reply with quote

That's not horrible to ask?

How that could be a problem? Our staff is irl's friends and we are running it together since a year now.. Would just make possible for them to see it. Just an option as getprop.password working.... You can use it or not that's it... Even if it's added you can take your own decision about "do I use it or not"..

Author Message
CWO



Joined: 04 Feb 2006
Posts: 691
Location: Chicago, IL USA

PostPosted: Fri Feb 22, 2008 9:31 pm    Post subject: Reply with quote

Well it would all depend on if the passwords are even saved as pure text in the accounts.txt file (pol.cfg option) because POL can't reverse an MD5 hashed password.

Author Message
MontuZ
Distro Developer


Joined: 10 Feb 2006
Posts: 293
Location: Myrtle Beach, South Carolina

PostPosted: Sat Feb 23, 2008 6:23 am    Post subject: Reply with quote

Eddyboy, reading your post just gave me an idea.

Anytime someone creates a new account or changes their password just;
account.SetProp("Password", new_password);

That way later you can just;
account.GetProp("Password");

If you want to grab it.

Cool

Author Message
*Edwards



Joined: 29 Dec 2007
Posts: 85
Location: Montreal, Canada

PostPosted: Mon Feb 25, 2008 3:56 am    Post subject: Reply with quote

That could be a solution obviously but still add unecessary data. But anyways, I shall simply deal with a password re-sender or something similar. Thanks anyway.

Author Message
Pierce



Joined: 02 Feb 2006
Posts: 256

PostPosted: Tue Feb 26, 2008 7:27 pm    Post subject: Reply with quote

@Montuz:
Really a good idea. For security reasons i would choose a datafile for that, so its not quite that open if somebody perhaps infiltrated that server searching the account files.

Post new topic   Reply to topic    PenUltima Online Forum Index -> Feature Suggestions All times are GMT - 4 Hours
Page 1 of 1

 




Powered by phpBB © 2001, 2005 phpBB Group :: Theme & Graphics by GHS & Scott E. Royalty