Back to TF Net

From: Ted Brindle <Ted_Brindle@spider
To: Daniel O'Leary
Subject: Re: ftp support
Date:Fri, February 27, 1998 08:57 PM


If the user does not know the password then the logical thing would be for them to re-register. If you know them, and they do not know their password there will be no difference as long as you can make the change. Somehow or other you will have to transmit the new password to them. There is a greater amount of security in having a hidden password than one that can easily be viewed.

This may not be an issue if you are running the system out of your home. I run a system from my home and this is not a problem for me there. I am faced with a side that prefers First Class. In First Class you cannot view your client passwords. This is a must for our department.

Telefinder would also benefit by having case sensitive passwords, and an automated password change such as that in Eudora.

The fewer steps the better.


Many people believe there is no need for the system administrator to see user passwords, if they still retain the authority to (re)set them.

The only problem arises when a user known to the administrator asks the administrator to tell them what a lost/forgotten password is so they can continue using the system under their existing account. Under the proposed chang to UM, the administrator will not be able to give them any clues as to what the password is/was, but can reset it to some other value. What is lost is the ability of the admin to give the user that "subtle hint" that only they would know to determine forgotton password for themeselves. An admin who does not know his users probably cannot take good advantage of this.

The risk is that a person who is not the user, tricks the admin into changing the password, giving them access to the unsuspecting user's account and inturn denying them legitimate access to their account because they do not know about the password change. You should ensure that your director understands ana accepts this tradeoff. Before TF is changed to support this, I think all sysops should understand it also.


23


Running TeleFinder Server v5.7.
© Copyright Spider Island Software