PHP Web Host - Quality Web Hosting For All PHP Applications Free RavenNuke(tm) Add Ons
  Login or Register
 • Home • Downloads • Your Account • Forums • 

View next topic
View previous topic


Google
 
Web RavenPHPScripts (This Site)
Post new topic   Reply to topic
Author Message
TAd
Worker
Worker


Joined: Oct 11, 2004
Posts: 104
Location: Oregon, USA

PostPosted: Sun Mar 20, 2011 3:19 pm Reply with quote Back to top

With regard to the creation of passwords/passkey, I like to see user details to aid in the creation of the stored passkey. For example, password and UserEmail (as salt) encrypted is a stored encrypted passkey. It would be unlikely to have 2 users who have the same password and email. Later if the email is changed, you could force a new password entry as well.

I think the security issues I have seen with regard to passwords is more along the lines of a very weak password, and not the way it was stored. A built in password generation would be a nice little feature. Forcing the use of stronger passwords would also be nice. Little Johny can have the best system on the backend, but if he uses aaa as a password, well... Little Johny will most likely be trying to sell pharmaceuticals Rolling Eyes.
View user's profile Send private message Yahoo Messenger
duck
Involved
Involved


Joined: Jul 03, 2006
Posts: 267

PostPosted: Sun Mar 20, 2011 3:48 pm Reply with quote Back to top

Eventually I would probably like to add individual unique salts which then have to be stored in table with users but as is what I have done should beef up security ten fold anyway.
View user's profile Send private message
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Forums ©
 

All logos and trademarks in this site are property of their respective owner.
The comments are property of their posters, all the rest © 2002-2011 by Raven

You can syndicate our news using the file xml

CSE HTML Validator Helped Clean up This Page! [Valid RSS] valid RSS 2.0 Valid robots.txt Stop Spam Harvesters, Join Project Honey Pot

Website engines core code is © copyright by PHP-Nuke but has been heavily patched and modified by myself and others.
PHP-Nuke is a free software released under the GNU/GPL.


:: fisubice phpbb2 style by Daz :: PHP-Nuke theme by www.nukemods.com ::
:: fisubice Theme Modified by the RavenNuke™ Team ::

:: W3C CSS Compliance Validation :: W3C HTML 4.01 Transitional Compliance Validation ::

zerosum