9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
* [9fans] plain passwords and keyfs
@ 2004-07-23 13:14 Enrique Soriano Salvador
  2004-07-23 16:10 ` Charles Forsyth
  0 siblings, 1 reply; 14+ messages in thread
From: Enrique Soriano Salvador @ 2004-07-23 13:14 UTC (permalink / raw)
  To: Fans of the OS Plan 9 from Bell Labs

Why does keyfs serve the users password in plain text on the file
/mnt/keys/user/secret ?

I know that the man in front of the
cpu/auth server is the only one that can see the users passwords...  but
it can be dangerous for users that have the same
password for different systems (unix,
win, plan9 ...)

{ I am changing my Unix passwords
in this very moment, so nemo and gorka can now see my password-for-all
in plain text!!! :) }

As far as I know, in other systems (i.e. unix) the admin cannot  see the
users passwords (of course, he can try to crack the /etc/shadow file or
to make other malicious acts)

I am sure that there is a design related
explanation for that...

Thanks!

Q.





^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2004-07-25 20:00 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <5d791b8fa2a574fb6cc322e97696054c@terzarima.net>
2004-07-23 17:46 ` [9fans] plain passwords and keyfs Enrique Soriano
2004-07-24  8:45   ` Charles Forsyth
2004-07-24 13:48     ` Steve Simon
2004-07-25 19:19       ` Charles Forsyth
2004-07-25 20:00         ` Steve Simon
2004-07-23 13:14 Enrique Soriano Salvador
2004-07-23 16:10 ` Charles Forsyth
2004-07-23 16:34   ` Wes Kussmaul
2004-07-23 16:47     ` andrey mirtchovski
2004-07-23 17:38       ` Wes Kussmaul
2004-07-23 17:06     ` Skip Tavakkolian
2004-07-24  7:32       ` Sam
2004-07-23 17:29         ` andrey mirtchovski
2004-07-23 23:24         ` Bruce Ellis

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).