Re: Re: Encrpted Passwords

droolin <[email protected]>
Newsgroups gmane.network.irc.bopm
Message-ID <[email protected]>
> 
> From: Erik Fears <[email protected]>
> Date: 2003/11/07 Fri PM 12:18:53 EST
> To: droolin <[email protected]>
> CC: Philipp Kern <[email protected]>, 
> 	Wayne <[email protected]>,  [email protected]
> Subject: Re: Re: [bopm] Encrpted Passwords
> 
> On Fri, Nov 07, 2003 at 12:08:47PM -0500, droolin wrote:
> > You know, i've thought about this a couple times myself and have to agree with Philipp.  I kind of came to the following security procedures to make life more difficult for security purposes:
> > 1). Each shell has a unique passowrd for the bopm.
> > 2). The bopm password found in the unreal conf for oper purposes is cyrpted.
> > 3). The bopm only requires an global oline, they should not be able to cause much damage.
> 
> Local, I hope. BOPM should not require global privledges.
> 
> 
> > 4). A csop/netadmin has the ability to remove oline status online if a security break occurs.(svsmode I think)  Worse case, jupe the server. Id do that anyway, just because it was a security leak/problem.  At least till the security issue was resolved.
> 
> This is false security. You should prevent the passwords from being compromised in the first place.

I agree with this totally.  This is what I was trying to say, that if the password was compromised then someone was in the shell.  I would hope that security is such that only designated individuals would have access to this.   But, again.  I agree with you totally.

> 
> > 
> > I look at it this way, if the bopm oper password is compromised.  It is most likely due to a person has had access to the shell, and was able to acquire this information.  If a person has access to a shell, they can create their own oline.  So, crypting the bopm password really dont accomplish anything.  Again, another reason to just jupe the server.
> 
> Why if the person has access to the shell they can create their own? This would only happen if BOPM was running from the same shell as the ircd.
> 
> -Erik
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.