×
  • remind me tomorrow
  • remind me next week
  • never remind me
Subscribe to the ANN Newsletter • Wake up every Sunday to a curated list of ANN's most interesting posts of the week. read more

Forum - View topic
Password problem!!!




Anime News Network Forum Index -> Site-related -> Bugs & Technical Questions
View previous topic :: View next topic  
Author Message
neonsign



Joined: 21 Apr 2013
Posts: 3
PostPosted: Sun Apr 21, 2013 4:14 am Reply with quote
I just registered to your site, and received an email giving further instructions to activate my account.

And what's creepy about that is, that i received my password in PLAINTEXT. Is this how you store our passwords in your database?

You should start worrying about that couse its NOT the right way of doing that. Either save HASH of the password or the SaltedHASH of it (more secure).

Please consider this.

Best regards
Back to top
View user's profile Send private message
Dan42
Chief Encyclopedist


Joined: 02 Jan 2002
Posts: 3782
Location: Montreal
PostPosted: Sun Apr 21, 2013 8:48 am Reply with quote
I admit it's ridiculous to send the plaintext password in an email. That's just how old and retarded phpBB2 is. But only the hash of the password is stored in the database.
Back to top
View user's profile Send private message Visit poster's website AIM Address My Anime My Manga
neonsign



Joined: 21 Apr 2013
Posts: 3
PostPosted: Sun Apr 21, 2013 9:14 am Reply with quote
If its stored as hash how its possible to send me back the plaintext of it.

I suggest you to take a little time and 'maintain' some tiny parts of your code and get it fixed, because sooner or later this vulnerability gonna cost much more.

Just saying, you know.
I wouldn't want anyone to have even the smallest possibility to gain access over my account.
Back to top
View user's profile Send private message
Tony K.
Subscriber
Moderator


Joined: 18 Nov 2003
Posts: 11293
Location: Frisco, TX
PostPosted: Sun Apr 21, 2013 6:08 pm Reply with quote
Why would someone care to hack an ANN account anyway? I mean, the most they could find out is an email address, unless you're just hiding all kinds of important names and numbers throughout your "my ANN" tabs, which I really don't recommend.
Back to top
View user's profile Send private message My Anime My Manga
dtm42



Joined: 05 Feb 2008
Posts: 14084
Location: currently stalking my waifu
PostPosted: Sun Apr 21, 2013 7:02 pm Reply with quote
^
Well Tony K., if someone hacked ANN and nabbed your password they could wreck all kinds of havoc with your Mod powers. Heck, even if you weren't a Moderator they could still make insulting, derogatory and abusive posts in your name and hurt your reputation before the Mods finally shut them down. Heck, if they really wanted to land you in hot water they'd use your account to directly post child porn pictures on the forum. Even if it could be easily disproved that it wasn't you who posted them, it would still be an extremely uncomfortable experience for you.

So I can see why some people would be a bit nervous if they believe - rightly or wrongly - that their password is not secure.

Now, I have no idea if the passwords are securely stored, but since I've never heard of ANN login passwords being stolen before, and since Dan42 isn't fretting over it, I'm not going to be losing much sleep over the matter. Obviously the OP is a bit more cautious than I am.
Back to top
View user's profile Send private message My Anime
Tony K.
Subscriber
Moderator


Joined: 18 Nov 2003
Posts: 11293
Location: Frisco, TX
PostPosted: Sun Apr 21, 2013 7:29 pm Reply with quote
Well if someone wanted wreck havoc around the Internet, I think they could probably find a better place to do it than a website full of anime/manga/Japanese-related news. People who generally have that kind of god complex more than likely wouldn't limit themselves to such esoteric groundings anyway. And if they did hack someone's account just to defame the person, then it's likely more so a personal vendetta, which would just be sad and pathetic to even commit in the first place. It's like saying, "I have all these super hacking skills, but instead of making money off of it, I'm gonna' pretend to be this other guy and make him look bad! Mwa ha ha ha~!"

It'd be like some 4th-rate villain out of a character lineup in Despicable Me. The least they can do is show a little more ambition.
Back to top
View user's profile Send private message My Anime My Manga
Rhyono



Joined: 03 Dec 2011
Posts: 1039
PostPosted: Sun Apr 21, 2013 10:21 pm Reply with quote
neonsign wrote:
If its stored as hash how its possible to send me back the plaintext of it.


When you register for the site, you are entering your password as plain text. Once you submit it, two things are done:

  1. It is sent to you the way you entered it (i.e. plain text).
  2. It is hashed and stored in the database.


As long as you can keep your email account secure: being sent your password to a forum is not the end of the world.
Back to top
View user's profile Send private message My Anime
Dessa



Joined: 14 Jul 2004
Posts: 4438
PostPosted: Sun Apr 21, 2013 11:02 pm Reply with quote
I should point out, knowing phpBB2 and phpBB3, that however the password is saved, the database can't recover it for you, nor can an administrator access your password (they can change it, but they can't see what it is).
Back to top
View user's profile Send private message My Anime
Rhyono



Joined: 03 Dec 2011
Posts: 1039
PostPosted: Sun Apr 21, 2013 11:50 pm Reply with quote
Dessa wrote:
however the password is saved, the database can't recover it for you


That's because the password is saved as a hash.
Back to top
View user's profile Send private message My Anime
neonsign



Joined: 21 Apr 2013
Posts: 3
PostPosted: Mon Apr 22, 2013 7:05 am Reply with quote
this helped me more than enough.
thanks a lot bros.

this did bring my sleep back.
cheers Very Happy
Back to top
View user's profile Send private message
Shiroi Hane
Encyclopedia Editor


Joined: 25 Oct 2003
Posts: 7580
Location: Wales
PostPosted: Tue Apr 23, 2013 10:15 am Reply with quote
dtm42 wrote:
^
Well Tony K., if someone hacked ANN and nabbed your password they could wreck all kinds of havoc with your Mod powers.

Staff have to have stronger password than other members. Dan has checks in place.
Back to top
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number My Anime My Manga
Rhyono



Joined: 03 Dec 2011
Posts: 1039
PostPosted: Tue Apr 23, 2013 8:13 pm Reply with quote
@Shiroi Hane Biometrics, with a dongle, password, key code, IP, Mac, and (assuming Windows) the unique ID? Or just more complex passwords?
Back to top
View user's profile Send private message My Anime
dtm42



Joined: 05 Feb 2008
Posts: 14084
Location: currently stalking my waifu
PostPosted: Tue Apr 23, 2013 8:48 pm Reply with quote
Back to top
View user's profile Send private message My Anime
Keonyn
Subscriber



Joined: 25 May 2005
Posts: 5567
Location: Coon Rapids, MN
PostPosted: Tue Apr 23, 2013 8:52 pm Reply with quote
Yeah, that seems about right.
Back to top
View user's profile Send private message Visit poster's website My Anime My Manga
Tony K.
Subscriber
Moderator


Joined: 18 Nov 2003
Posts: 11293
Location: Frisco, TX
PostPosted: Tue Apr 23, 2013 9:12 pm Reply with quote
And I often feel like a lot of users have hearing impairments from the Cone of Silence...
Back to top
View user's profile Send private message My Anime My Manga
Display posts from previous:   
This topic is locked: you cannot edit posts or make replies.    Anime News Network Forum Index -> Site-related -> Bugs & Technical Questions All times are GMT - 5 Hours
Page 1 of 1

 


Powered by phpBB © 2001, 2005 phpBB Group