FusionBB
FusionBB Review (large)
Recent Members
Welcome them to our community!
FusionBB SWAG!

FusionBB golf shirts, t-shirts, mousepads and more.

Tagging
FusionBBDev Recent Topics
Username Post: SSL login        (Topic#11783)
Laree Draper
FusionBB Enthusiast
Total Posts: 246
*
Average Post Ranks%:                       
11-10-10 08:36 PM - Post#84858    



One of our forum members pointed out that our registration and logins should go to a secure layer, then back to the regular layer for reading and posting. His thought was if someone's at a coffee shop and logs in, someone on wifi could grab the password, which maybe the member uses on other sites.

Do I have something set up wrong, or is there a fix for this?

Site is

http://www.davedraper.com/fusionbb/index...

... if you need to see what's going on... but I assume everyone's setup is the same, no?

Thanks.

IronOnline weight training and nutrition forum
http://www.davedraper.com/fusionbb/index...


 
Couchtomatoe
Code Monkey
Total Posts: 3049
*
Birthday: 02-03 
Location: Richmond, Virginia
Average Post Ranks%:                       
 
11-11-10 09:29 AM - Post#84859    


    In response to Laree Draper

Passwords are NOT sent as clear text they are sent as an md5 hash so they are secure enough for a forum. If someone was to grab your password like he is explaining it could be eventually converted back to a clear text password but they would have to jump over many hoops.
The artist formerly known as scroungr
Couch-Tomatoe


 
Laree Draper
FusionBB Enthusiast
Total Posts: 246
*
Average Post Ranks%:                       
11-11-10 09:57 AM - Post#84860    


    In response to Couchtomatoe

Oh, excellent, thanks very much!
IronOnline weight training and nutrition forum
http://www.davedraper.com/fusionbb/index...


 
Couchtomatoe
Code Monkey
Total Posts: 3049
*
Birthday: 02-03 
Location: Richmond, Virginia
Average Post Ranks%:                       
 
11-11-10 10:02 AM - Post#84861    


    In response to Laree Draper

and this doesn't mean we can;t get better.. in 3.2 we will introduce salted passwords and maybe ssha1 passwords.. but its not something the user will see.. its all back end.. But if the user is concerned that their password will be cracked then maybe they need to store them better because while passwords can be brute forced (not cracked more of a guess) there shouldn't be anything on a forum that they wouldn't want to tell their mother.. or lawyer..
The artist formerly known as scroungr
Couch-Tomatoe


 
Icon Legend Permissions & Sharing Options Topic Options
Print Topic


380 Views
Calendar
SMTWTFS
 1234
567891011
12131415161718
19202122232425
262728293031 
Current Quote
"Just signed on today and what I see I like very much. I am impressed with the features, especially the private topic idea - a stroke of genius."
~ Bear
FusionBB™ Version 3.2 | ©2003-2013 InteractivePHP, Inc.
Execution time: 0.052 seconds.   Total Queries: 105   Zlib Compression is on.
All times are (GMT-4). Current time is 08:57 AM
Top