| | | Quote of the month: "If you judge people, you have no time to love them." ~ Mother Teresa |
| | | 
28-05-08, 04:06 AM
|  | Nugget of Love | | Join Date: Nov 2006
Gender:
Posts: 4,124
My Mood: Thanks: 352
Thanked 192 Times in 166 Posts
| | | Is loveforum login really secure? <form action="http://www.loveforum.net/login.php?do=login" method="post" onSubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">
I never really bothered to look until just now. How come SSL isn't being used? Or HTTPS? Is md5hash really secure?  | | Loveforum Breaktime | | |  | Loveforum also recommend - Green tea - Help in weight loss and decrease rate of getting cancer.
| | 
28-05-08, 04:10 AM
|  | Super Moderator | | Join Date: Feb 2006 Location: Santa Fe
Gender:
Posts: 10,134
Thanks: 572
Thanked 725 Times in 601 Posts
| | | No idea. I just do stuff on the front end, not the back end.
__________________ I think all women really want is to be proven wrong about men. | | 
28-05-08, 04:13 AM
|  | Nugget of Love | | Join Date: Nov 2006
Gender:
Posts: 4,124
My Mood: Thanks: 352
Thanked 192 Times in 166 Posts
| | | Completely understandable, I am expecting an answer from loveadmin, because I doubt any moderators deal with server-end applications.
Also expecting some debate from technical users who know a bit about that.
My understanding is that MD5 is quite insecure, and I am just suggesting that SSL/HTTPS be used instead.
__________________
If you stare at a white pixel long enough, you notice the throbbing red, green, and blue elements that create it.
If you stare at a fuzzy blanket long enough with your eye so close it goes out of focus, just look at the sparkles; you can see it on the cellular level.
| | 
28-05-08, 05:59 AM
|  | Transient sentient. "Hot Love Pancake(s)" | | Join Date: Jul 2007
Posts: 2,538
Thanks: 744
Thanked 701 Times in 589 Posts
| | | Not a direct answer, but a caution for the unwary:
Nothing you commit to the internet should be considered secure. Emails can be read by system admins, IP addressses can be traced (sometimes), that sort of thing. There are ways to check who's looking (we look periodically to see who has pinged our computers) & its sometimes interesting to see what you find.
Its that old saying: if you don't want to be held accountable for saying it, don't say it.
__________________ A woman would never make a nuclear bomb. They would never make a weapon that kills, no, no. They'd make a weapon that makes you feel bad for a while. | | 
28-05-08, 06:46 AM
|  | Nugget of Love | | Join Date: Nov 2006
Gender:
Posts: 4,124
My Mood: Thanks: 352
Thanked 192 Times in 166 Posts
| | Words of wisdom from Indi; of course precautions should be taken into consideration. But what I am getting at is even more important; the user login of the forum uses an algorithm of cryptography, called MD5, which is known for its simple vulnerabilities. Its hashes are easily decoded, because they are very simply encrypted. What does this mean? Well, someone that knows what they are doing could phish a page to you, because it is not HTTPS, and get your username and password. They could also retrieve the hash of the username/password and decrypt it, and have access to your account here (and possibly other websites, and more personal information if you use the same password for everything)
As I recall, this has happened already with one account (Dono) and vulnerability remains open.
I am just looking out for this community by examining the issue. Time and time again in my experience as a server specialist and web designer, my opinion is that users tend to use the same username/password for everything. I am informing the public about this, and hopefully they will make any necessary changes, to ensure their security, but it is not guaranteed.
I also think it is the duty of administrative staff, even moderators on forums, to do everything they can, within reasonable boundaries, to eliminate any such problems. Why? Well, that is how the successful websites do it. The mindset of "Pfft, well that's just how the Internet is," is somewhat hindering, because it is, in a way, avoiding a problem. Sure, that's how the Internet is now, but it is not adamant. It can be changed, for the better, or for the worse. I am here to make it for the better, as I see it. Don't you want that? Don't you care?
And from a philosophical point, nothing in this world is secure. Nothing is symmetrical. So this lesson can be applied to actual life, too. I am actually writing about that in my freetime. A life of independence is a perfect one.
Oh, and I want to be recognized for the things I say. Even on here. I take full credit for all of it, but unfortunately, some sneaky bastard will probably take that away from me. Oh well. Hopefully what I said was so cleverly toned and original, that nobody could ever imitate it and call it their own. HA! 
__________________
If you stare at a white pixel long enough, you notice the throbbing red, green, and blue elements that create it.
If you stare at a fuzzy blanket long enough with your eye so close it goes out of focus, just look at the sparkles; you can see it on the cellular level.
Last edited by anachronistic : 28-05-08 at 06:57 AM.
| | 
29-05-08, 08:28 PM
|  | Incongruant | | Join Date: Apr 2004 Location: Land of tea and crumpets.
Gender:
Posts: 4,221
My Mood: Thanks: 160
Thanked 75 Times in 58 Posts
| | | I don't think anyone really cares to be honest. | | The Following User Says Thank You to Kiechi For This Useful Post: | | | 
29-05-08, 08:54 PM
|  | Live with passion | | Join Date: Sep 2001
Gender:
Posts: 598
My Mood: Thanks: 0
Thanked 18 Times in 15 Posts
| | | Sorry for the late answer. Just to assure everyone that the login is secure.
__________________
Loveadmin "It is not length of life, but depth of life." -- Ralph Waldo Emerson
| | 
30-05-08, 10:22 AM
| | different state of mind | | Join Date: Sep 2001
Gender:
Posts: 12,649
My Mood: Thanks: 12
Thanked 259 Times in 218 Posts
| | | yup, i don't really care. that's why i have a million and one passwords.. i have to write everything down to keep track of them. of course i lock them in my safe that has the same combination as my birthday so that i will never forget it. i'm all good.
raverboy
__________________
...this is just my perspective on the situation...
| | The Following User Says Thank You to Illusional For This Useful Post: | | | 
04-06-08, 10:07 AM
|  | Registered User | | Join Date: Dec 2007
Gender:
Posts: 608
Thanks: 174
Thanked 174 Times in 134 Posts
| |
Originally Posted by Illusional yup, i don't really care. that's why i have a million and one passwords.. i have to write everything down to keep track of them. of course i lock them in my safe that has the same combination as my birthday so that i will never forget it. i'm all good.
raverboy lol. Your SO, family, or friends can break into home and get it. | | 
04-06-08, 04:04 PM
|  | Live with passion | | Join Date: Sep 2001
Gender:
Posts: 598
My Mood: Thanks: 0
Thanked 18 Times in 15 Posts
| |
Originally Posted by Illusional yup, i don't really care. that's why i have a million and one passwords.. i have to write everything down to keep track of them. of course i lock them in my safe that has the same combination as my birthday so that i will never forget it. i'm all good.
raverboy Just wonder is rboy drunk while writing this? 
__________________
Loveadmin "It is not length of life, but depth of life." -- Ralph Waldo Emerson
| | The Following User Says Thank You to loveadmin For This Useful Post: | | | 
05-06-08, 09:57 AM
| | different state of mind | | Join Date: Sep 2001
Gender:
Posts: 12,649
My Mood: Thanks: 12
Thanked 259 Times in 218 Posts
| | | i probably was drunk when i wrote that. or atleast i thought i was.
raverboy
__________________
...this is just my perspective on the situation...
| | 
06-06-08, 10:14 AM
|  | Nugget of Love | | Join Date: Nov 2006
Gender:
Posts: 4,124
My Mood: Thanks: 352
Thanked 192 Times in 166 Posts
| | | I never pictured raverboy as such a paranoid. Tell me, raverboy, do you insert your butt plug every day to keep yourself on your toes?
Anyway, I actually just used md5 to encrypt a user database on a website I am designing; first I encrypt it with md5, and then it is encrypted again with the MySQL encryption. And then the login uses SSL for maximum security.
__________________
If you stare at a white pixel long enough, you notice the throbbing red, green, and blue elements that create it.
If you stare at a fuzzy blanket long enough with your eye so close it goes out of focus, just look at the sparkles; you can see it on the cellular level.
| | 
07-06-08, 10:34 AM
| | different state of mind | | Join Date: Sep 2001
Gender:
Posts: 12,649
My Mood: Thanks: 12
Thanked 259 Times in 218 Posts
| |
Originally Posted by lilwing I never pictured raverboy as such a paranoid. Tell me, raverboy, do you insert your butt plug every day to keep yourself on your toes?
Anyway, I actually just used md5 to encrypt a user database on a website I am designing; first I encrypt it with md5, and then it is encrypted again with the MySQL encryption. And then the login uses SSL for maximum security. paranoid?? i only keep my butt plug in because i'm worried that gay people like you want to stick your thing up my ass.
raverboy
__________________
...this is just my perspective on the situation...
| | 
09-06-08, 10:40 AM
|  | Moderator | | Join Date: Jul 2005 Location: Colorado
Posts: 2,406
Thanks: 0
Thanked 4 Times in 3 Posts
| | | MD5 is definitely secure, but you still have to use a somewhat complex password. If you use the word apple, for example, it wouldnt be that hard to figure out even with md5. But there is one thing to always keep in mind, on any site ask yourself, is someone really going to spend that much time and that much computing power to try and access your account on said site. I can bet nobody is going to put in such effort to get your loveforum pass
__________________
"Oh Lord it's hard to be humble, when you're perfect in every way. I can't wait to look in the mirror, cause I get better loking each day. To know me is to love me, I must be a hell of a man. Oh Lord it's hard to be humble, but I'm doing the best that I can." Mac Davis
| | 
10-06-08, 10:18 PM
|  | Live with passion | | Join Date: Sep 2001
Gender:
Posts: 598
My Mood: Thanks: 0
Thanked 18 Times in 15 Posts
| |
Originally Posted by TAVS MD5 is definitely secure, but you still have to use a somewhat complex password. If you use the word apple, for example, it wouldnt be that hard to figure out even with md5. But there is one thing to always keep in mind, on any site ask yourself, is someone really going to spend that much time and that much computing power to try and access your account on said site. I can bet nobody is going to put in such effort to get your loveforum pass TAVS! long time never see you here.
Our server is going move to denver, colorado very soon. I bet you will get a good ping from your home next week onward. 
__________________
Loveadmin "It is not length of life, but depth of life." -- Ralph Waldo Emerson
| | Loveforum Breaktime | | |  | Loveforum also recommend - Green tea - Help in weight loss and decrease rate of getting cancer.
| | | Thread Tools | | | | Display Modes | Rate This Thread | Linear Mode | |
Posting Rules
| You may not post new threads You may not post replies You may not post attachments You may not edit your posts HTML code is Off | | | All times are GMT +8. The time now is 11:51 AM. | |