[IRCServices] secure Identify Feature..

M mark at ctcp.net
Tue Apr 13 16:08:45 PDT 2004


Craig McLure wrote:
> This command would add things to make the channel more secure 
> thou, If you did give the channel founder password to people 
> you trust, and you find its being abused, you can simply 
> remove that person from the access list, this way you dont 
> need to worry about changing the password and re-distributing it :) 

The way to be secure is not to give out the founder password. You could
apply the same short sighted reason for a "/ns set
letotherpeopleaccessmynick pass" request. 

The founder password is designed to give the channel founder access to
manage the ownership of the channel. There is no need to give out the
password to anyone, channel management through others is provided via op
status. 

If for some peculiar reason a channel founder wishes to share the password
then IMO that is their problem. The chances are that any user that would
require modifying the access list to "fix" this, would likely be attempted
too late since a rogue user could have merely taken ownership of the channel
thereby making the option and the founder password redundant and merely make
it a problem that administrators waste time on. 

The founder can already provide access to whatever commands an op needs via
levels which is far more secure and already subject to access list
restrictions. 

What function of founder status is required that warrants removing the
founder status by supporting sharing of it? 

M.