No, there's no mechanism for hashing or encrypting the passwords in the Synchronet userbase (today, that's data/user/user.tab). A one-way hash would be particularly tricky because Synchronet supports a bunch
of
digest-based authentication methods that all require different hashes of the password along with challenge/nonce/sale (so you need the original password to compute those).
We could encrypt the passwords on disk (reversable to plaintext again, for the above stated reasons), but then you need to have/store a key to decrypt them somewhere and how is that any more secure than the
user.tab file? It's a can of worms that hasn't be worth dumping out and sorting through.
have/store a key to decrypt them somewhere and how is that any more
secure than the user.tab file? It's a can of worms that hasn't
be worth dumping out and sorting through.
| Sysop: | KrAAB |
|---|---|
| Location: | Donna, TX |
| Users: | 4 |
| Nodes: | 10 (0 / 10) |
| Uptime: | 103:34:21 |
| Calls: | 56,978 |
| Files: | 3,314 |
| D/L today: |
20 files (9,999K bytes) |
| Messages: | 52,709 |