Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revision | |||
| module:rlogin [2025/04/19 19:35] – [Auto-Login] Document the -H option digital man | module:rlogin [2025/12/13 17:34] (current) – [Auto-Login] fixed typos digital man | ||
|---|---|---|---|
| Line 78: | Line 78: | ||
| Hashed passwords can be used to securely authenticate the local BBS user with the remote RLogin server without leaking the user's local password. | Hashed passwords can be used to securely authenticate the local BBS user with the remote RLogin server without leaking the user's local password. | ||
| - | In some use cases, the RLogin server may be expected store/ | + | In some use cases, the RLogin server may be expected |
| The '' | The '' | ||
| - | The user's password, user number, and account creation date are used to generate the password hash, so changing any of these values will change the resulting hashed password sent (and presumably logged/ | + | The user's password, user number, and account creation date are used to generate the password hash, so changing any of these values will change the resulting hashed password sent to (and presumably logged/ |
| Included in the hashed parameters are so-called //salt// and //pepper// (strings of characters) to help insure that the a user with the same number, password, and creation date on another BBS won't generate the same hash value that is sent to the RLogin server (allowing a malicious server to identify users with same passwords). | Included in the hashed parameters are so-called //salt// and //pepper// (strings of characters) to help insure that the a user with the same number, password, and creation date on another BBS won't generate the same hash value that is sent to the RLogin server (allowing a malicious server to identify users with same passwords). | ||
| Line 95: | Line 95: | ||
| When multiple 3rd party RLogin servers are being connected to with hashed passwords, it is recommended to include a different pepper value for each RLogin server, e.g. '' | When multiple 3rd party RLogin servers are being connected to with hashed passwords, it is recommended to include a different pepper value for each RLogin server, e.g. '' | ||
| - | Including pepper allows server-unique hashes so that if one BBS auto-registers/ | + | Including pepper allows server-unique hashes so that if one BBS auto-registers/ |