Download Game! Currently 128 players and visitors. Last logged in:BlnkShendericAlistarPisano

BatMUD Forums > Ideas-wanted > Re: please increase password length

 
 
#1
30 Nov 2013 16:03
 
 
help password ->
Note that only the first 8 characters are significant!

8 characters maximum is pretty shabby by todays standards. Please increase the
maximum length. I'm fine with 30 characters, someone might like longer still,
who knows.

++glaurung

 
Rating:
13
Votes:
13
 
 
Glaurung
3y, 65d, 17h, 49m, 51s old
Level:
60
 
 
#2
01 Dec 2013 04:05
 
 
Glaurung wrote:
help password ->
Note that only the first 8 characters are significant!

8 characters maximum is pretty shabby by todays standards. Please increase the
maximum length. I'm fine with 30 characters, someone might like longer still,
who knows.

++glaurung
Considering that we send it over telnet protocol i would assume it to be
quite irrelevant to go for crazy lenghts unless plan is to increase password
reset rate :D
v

 
Rating:
2
Votes:
2
 
 
Xunisiih
4y, 222d, 11h, 39m, 13s old
Level:
104
 
 
#3
01 Dec 2013 10:08
 
 
Xunisiih wrote:
Considering that we send it over telnet protocol i would assume it to be
quite irrelevant to go for crazy lenghts unless plan is to increase password
reset rate :D
v
BatMUD can also be accessed with telnet over SSL, by connecting
to: batmud.bat.org 2022

Some MUD clients support this, and batclient uses SSL by default.

Alternatively you can setup a SSL tunnel (using stunnel or similar)
and have an encrypted connection to BatMUD using your MUD client of
choice.

++ Gore

 
Rating:
1
Votes:
1
 
 
Gore
A r c h w i z a r d
14y, 107d, 7h, 22m, 21s old
Level:
600 [Wizard]
 
 
#4
03 Dec 2013 04:30
 
 
Xunisiih wrote:
Glaurung wrote:
help password ->
Note that only the first 8 characters are significant!

8 characters maximum is pretty shabby by todays standards. Please increase the
maximum length. I'm fine with 30 characters, someone might like longer still,
who knows.

++glaurung
Considering that we send it over telnet protocol i would assume it to be
quite irrelevant to go for crazy lenghts unless plan is to increase password
reset rate :D
The assumption that a password could only be acquired by snooping network
traffic is a faulty one, that scenario is very unlikely to happen in most
cases, I think. More likely scheme would be to brute-force. Of course the game
itself is somewhat resilient, due to the "guess wrong X times -> get a
cooldown", but perhaps the website does not have that .. I'm not sure.

--
Ggr "The Pessimist" Pupunen

 
 
 
Ggr
W i z a r d
3y, 127d, 17h, 40m, 50s old
Level:
54 [Wizard]
 
 
#5
03 Dec 2013 20:57
 
 
Glaurung wrote:
help password ->
Note that only the first 8 characters are significant!
Sounds an awful lot like someone's still using crypt(3) with DES ;)

 
 
 
Lotheac
147d, 9h, 45m, 14s old
Level:
67