View Single Post
  #10  
Old 03-17-2015, 09:15 PM
Secrets Secrets is offline
VIP / Contributor

Secrets's Avatar

Join Date: Oct 2009
Posts: 1,354
Default

Quote:
Originally Posted by jetviper21 [You must be logged in to view images. Log in or Register.]
That being said even the official tak login server will log your password in plain text to the servers log files.

https://github.com/cavedude00/Server....cpp#L199-L200

Another fun thing is that if you are on a mac and you run "ps aux | grep Everquest" you can see your password in plain text passed as a command line argument. So arguing security here has little merit in a system that has obvious flaws
It's an option and if it's a security concern I will personally remove it.

It's no different than the plaintext passwords being sent on the client to the EQ server, though that's more of a client restriction.
__________________
Engineer of Things and Stuff, Wearer of Many Hats

“Knowing yourself is the beginning of all wisdom.” — Aristotle