Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Discussion & Documentation Gentoo Forums Feedback
  • Search

Are passwords stored in plain text??

Having a problem with the forums? Have a suggestion? Post here!
Post Reply
  • Print view
Advanced search
9 posts • Page 1 of 1
Author
Message
shunk
n00b
n00b
Posts: 1
Joined: Tue Dec 24, 2019 8:00 pm
Location: Cobh, Ireland

Are passwords stored in plain text??

  • Quote

Post by shunk » Tue Dec 24, 2019 8:02 pm

When I signed up I recieved an email with my full on password, this means that passwords are stored in plaintext, right? Isn't that super bad?
Top
Ant P.
Watchman
Watchman
Posts: 6920
Joined: Sat Apr 18, 2009 7:18 pm
Contact:
Contact Ant P.
Website

  • Quote

Post by Ant P. » Tue Dec 24, 2019 8:47 pm

Passwords are hashed and you got it in plaintext because you just sent it in plaintext.

Not bad if you're managing your passwords properly, just change it again. It won't send another email.
Top
389292
Guru
Guru
Posts: 504
Joined: Tue Mar 26, 2019 2:06 pm

Re: Are passwords stored in plain text??

  • Quote

Post by 389292 » Tue Dec 24, 2019 9:34 pm

shunk wrote:When I signed up I recieved an email with my full on password, this means that passwords are stored in plaintext, right? Isn't that super bad?
Right. Yes it is.
Top
NeddySeagoon
Administrator
Administrator
User avatar
Posts: 56094
Joined: Sat Jul 05, 2003 9:37 am
Location: 56N 3W

  • Quote

Post by NeddySeagoon » Tue Dec 24, 2019 9:52 pm

Ant P. linked the forum code snippet above.
Passwords are hashed for storage.
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Top
gengreen
Apprentice
Apprentice
Posts: 150
Joined: Sat Dec 23, 2017 2:49 am
Contact:
Contact gengreen
Website

  • Quote

Post by gengreen » Wed Dec 25, 2019 12:00 pm

Right. Yes it is
I disagree, being worry about a password stored in clear is a security mistake at the first place. Never password reuse.
Top
389292
Guru
Guru
Posts: 504
Joined: Tue Mar 26, 2019 2:06 pm

  • Quote

Post by 389292 » Wed Dec 25, 2019 3:11 pm

gengreen wrote:
Right. Yes it is
I disagree, being worry about a password stored in clear is a security mistake at the first place. Never password reuse.
The question was not about worrying or best practices. The question was - is it bad or not, and yes it is bad no matter how skillful you are in shifting blame to your users. 50% of users do reuse their passwords, maybe not on this forum but still.
Top
Ant P.
Watchman
Watchman
Posts: 6920
Joined: Sat Apr 18, 2009 7:18 pm
Contact:
Contact Ant P.
Website

  • Quote

Post by Ant P. » Wed Dec 25, 2019 7:36 pm

To address the actual problem here: yes, phpBB's security when it was written 18 years ago was somewhat average for the period. It could be better.
The mail server uses TLSv1.2, so as long as the recipient isn't doing awful things like using a freemail account hosted by a data-harvesting panopticon, it's still safe. Security is a spectrum.

The email templates are here, ready and waiting whenever someone wants to volunteer to fix it. No programming knowledge beyond git-format-patch is needed, but it looks like nobody's found it urgent enough to actually fix.
Top
gengreen
Apprentice
Apprentice
Posts: 150
Joined: Sat Dec 23, 2017 2:49 am
Contact:
Contact gengreen
Website

  • Quote

Post by gengreen » Tue Jan 07, 2020 4:35 am

etnull wrote:
gengreen wrote:
Right. Yes it is
I disagree, being worry about a password stored in clear is a security mistake at the first place. Never password reuse.
The question was not about worrying or best practices. The question was - is it bad or not, and yes it is bad no matter how skillful you are in shifting blame to your users. 50% of users do reuse their passwords, maybe not on this forum but still.
If it was only the users the problem ok... but even IT professional are reusing (and other sector), we should insist on this as much as possible.

This problem is older than year 2000 and will remain for long, probably forever, despite an available solution of never reuse password.

Being said, pushing people to understand that hash/crypt password of the forum wouldn't be a concern if at the first place, password was uniq, saying it can't harm but saying the dev of Gentoo are doing bad practice do harm.
Less is best
Top
NeddySeagoon
Administrator
Administrator
User avatar
Posts: 56094
Joined: Sat Jul 05, 2003 9:37 am
Location: 56N 3W

  • Quote

Post by NeddySeagoon » Tue Jan 07, 2020 8:45 am

gengreen,

Reusing passwords is a social problem not a technical one.
The only technical solution is to design out passwords.

Welcome 1984
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Top
Post Reply
  • Print view

9 posts • Page 1 of 1

Return to “Gentoo Forums Feedback”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic