Encrypting users passwords

9 posts by 5 authors in: Forums > CMS Builder
Last Post: February 14, 2011   (RSS)

By Twocans - January 30, 2011

Hello,
I have just started to play with the cms for the virst time, all seems to be working and I am having fun.

But, I have created some user accounts as I am the admin. When I then use navicat to view my database I see that the passwords for both users and admin are not encryped, this is sometime I feel is very important. Is there something in the control panel that I can check that will make all passwords entered and saved encryped.


cheers

k

Re: [twocans] Encrypting users passwords

By Jason - January 31, 2011

Hi,

Currently CMS Builder doesn't support encrypting passwords in the database. This is something we're considering implementing in the future.

There is a trade off between security and usability. For example, if a user forgets their password, we have functionality that can send them a reminder of what their password is. If we encrypt the password, we would have to have them reset it.

That being said, CMS Builder is still a very secure piece of software. We've never had a customer have their server hacked as a result of our software.

Hope this helps.
---------------------------------------------------
Jason Sauchuk - Project Manager
interactivetools.com

Hire me! Save time by getting our experts to help with your project.
http://www.interactivetools.com/consulting/

Re: [Jason] Encrypting users passwords

By Twocans - February 1, 2011

Hello,
Thanks for your reply

re CMS Builder is still a very secure piece of software. We've never had a customer have their server hacked as a result of our software."

That is great to know. But I am just looking at things from my side, I usually use Navicat for my database, what if someone got access to that then got to the database and played silly buggers with the passwords etc.

I do think it is very important to have the encrypted passwords and would very much like to see it implemented in the future, even as a plugin which also offered captcha.

k

Re: [twocans] Encrypting users passwords

By pod9 - February 10, 2011

hi, my customer has just raised this same concern re passwords not being encrypted. is there any way to encrypt passwords at all?
Pod9

Re: [pod9] Encrypting users passwords

By Twocans - February 10, 2011

It would be great if something like this was added to all passwords entered both in the cms and the membership plugin.

http://pajhome.org.uk/crypt/md5/


kenny

Re: [twocans] Encrypting users passwords

By Twocans - February 10, 2011

Here I attach a page that encryots the password. To test it out you just need to put the testlogin.php and the testmd5 dir at root level and test the apge testlogin.asp

I am now trying to figure how I can add the md5 to the apsswords been inserted using the cms


k
Attachments:

testlogin-with-md5.zip 14K

Re: [twocans] Encrypting users passwords

By ross - February 10, 2011

Hi twocans

Thanks for posting the example. There is actually quite a bit of work that goes into updating CMS Builder to work with encrypted passwords so it's something we would end up working with you on through our consulting service (consulting@interactivetools.com). Drop me a line through that and we can go over the options.

Thanks!
-----------------------------------------------------------
Cheers,
Ross Fairbairn - Consulting
consulting@interactivetools.com

Hire me! Save time by getting our experts to help with your project.
Template changes, advanced features, full integration, whatever you
need. Whether you need one hour or fifty, get it done fast with
Priority Consulting: http://www.interactivetools.com/consulting/

Re: [twocans] Encrypting users passwords

By Damon - February 14, 2011

Hi,

Appreciate your feedback.

We do have those features on our CMS Builder Features Request but no time line is available for that right now.

Check back in the future and/or subscribe to our newsletter as we announce new versions and features of CMS Builder.

Thanks!
Cheers,
Damon Edis - interactivetools.com

Hire me! Save time by getting our experts to help with your project.
http://www.interactivetools.com/consulting/