password... password...
 

News:

CPG Release 1.6.26
Correct PHP8.2 issues with user and language managers.
Additional fixes for PHP 8.2
Correct PHP8 error with SMF 2.0 bridge.
Correct IPTC supplimental category parsing.
Download and info HERE

Main Menu

password...

Started by tanfwc, March 27, 2004, 06:50:53 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

tanfwc

why is the password in the database not in md5 hashes? it is in PLAIN TEXT...
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting

Joachim Müller

there has been a discussion about this a while ago, please search the board for "md5 AND password".
There's a mod available: http://forum.coppermine-gallery.net/index.php?topic=2179

GauGau

tanfwc

ok. Thanx. Why dun u put that function into this gallery?
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting

Joachim Müller

I hope you read the posting I was refering to: there's always ease of use against security: some people prefer having the passwords stored in plain text, because they run a gallery with newbie-users who forget their passwords every now and then: it's easier to look up their passwords if they're plain-text.
If someone hacks your site and is able to see your database (e.g. gains access to phpMyAdmin) and its contents, you probably have to worry about other things anyway...
The main reason why this hasn't been done yet I guess is: it simply has been forgotten. There are so many features that are being considered when developing a new version: sometimes you simply forget about stuff you were thinking about before.

GauGau

tanfwc

does this md5 feature install in the future versions?
tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting

Joachim Müller

maybe, but it's not in cpg1.3.0, which is in the release pipeline.

GauGau

tanfwc

tanfwc
[ + ] My HomePage
[ + ] GuestBook
[ + ] Photo Gallery
[ + ] Free Image Hosting