From owner-freebsd-stable Mon Jul 29 2:20:59 2002 Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 7351037B400 for ; Mon, 29 Jul 2002 02:20:56 -0700 (PDT) Received: from raven.ravenbrook.com (raven.ravenbrook.com [193.82.131.18]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3C14143E67 for ; Mon, 29 Jul 2002 02:20:55 -0700 (PDT) (envelope-from nb@ravenbrook.com) Received: from thrush.ravenbrook.com (thrush.ravenbrook.com [193.112.141.249]) by raven.ravenbrook.com (8.11.6/8.11.6) with ESMTP id g6T9KMW67641 for ; Mon, 29 Jul 2002 10:20:22 +0100 (BST) (envelope-from nb@ravenbrook.com) Received: from thrush.ravenbrook.com (localhost [127.0.0.1]) by thrush.ravenbrook.com (8.12.2/8.12.2) with ESMTP id g6T9LPUK023865 for ; Mon, 29 Jul 2002 10:21:25 +0100 (BST) (envelope-from nb@thrush.ravenbrook.com) From: Nick Barnes To: freebsd-stable@freebsd.org Subject: telnet "SRA secure login" fails intermittently Date: Mon, 29 Jul 2002 10:21:25 +0100 Message-ID: <23864.1027934485@thrush.ravenbrook.com> Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG When I telnet into a FreeBSD box, I get this: $ telnet spong Trying 192.168.0.1... Connected to spong.my.domain Escape character is '^]'. Trying SRA secure login: User (nb): Password: If I mistype the password, I get this: [ SRA login failed ] User (nb): Password: And so on. Fair enough. But it has seemed to me that I have been "mistyping my passwords" much more often since about 4.1: maybe 20% of the time, as if somehow telnetd (or SRA, whatever that is) is getting the password check wrong intermittently. And If I fail a login the first time, it seems harder to pass it the second time (the ~20% failure rate goes up to maybe 50%). Recently I have run some little checks on this. Whenever I'm telnetting in from an xterm, if the first login fails, I type my password into another X app (so I can visually check it) and paste it from ther. Sometimes that login does also fail. So there's something wrong somewhere: xterm, telnetd, SRA (?). Unless this is a security "feature"?? Nick B To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message