Love Forum - Online Relationship Discussion
Quote of the month: "It is not the things we do in life that we regret on our death bed. It is the things we do not. Find your passion and follow it. " ~ Randy Pausch

 

Reply
 
LinkBack Thread Tools Rate Thread Display Modes
  #1 (permalink)  
Old 28-05-08, 04:06 AM
anachronistic
 
Posts: n/a
Is loveforum login really secure?
<form action="http://www.loveforum.net/login.php?do=login" method="post" onSubmit="md5hash(vb_login_password, vb_login_md5password, vb_login_md5password_utf, 0)">

I never really bothered to look until just now. How come SSL isn't being used? Or HTTPS? Is md5hash really secure?

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Loveforum Breaktime
love

Loveforum also recommend

  • Green tea - Help in weight loss and decrease rate of getting cancer.
  #2 (permalink)  
Old 28-05-08, 04:10 AM
Gigabitch's Avatar
Gigabitch Gigabitch is offline
Super Moderator
 
Join Date: Feb 2006
Location: Santa Fe
Gender: Female
Posts: 9,934
Thanks: 613
Thanked 797 Times in 643 Posts
Gigabitch is a splendid one to beholdGigabitch is a splendid one to beholdGigabitch is a splendid one to beholdGigabitch is a splendid one to beholdGigabitch is a splendid one to beholdGigabitch is a splendid one to beholdGigabitch is a splendid one to beholdGigabitch is a splendid one to behold
Send a message via AIM to Gigabitch
No idea. I just do stuff on the front end, not the back end.
__________________
I think all women really want is to be proven wrong about men.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 28-05-08, 04:13 AM
anachronistic
 
Posts: n/a
Completely understandable, I am expecting an answer from loveadmin, because I doubt any moderators deal with server-end applications.

Also expecting some debate from technical users who know a bit about that.

My understanding is that MD5 is quite insecure, and I am just suggesting that SSL/HTTPS be used instead.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 28-05-08, 05:59 AM
IndiReloaded's Avatar
IndiReloaded IndiReloaded is offline
Transient sentient.
"Hot Love Pancake(s)"
 
Join Date: Jul 2007
Posts: 3,061
Thanks: 1,036
Thanked 1,002 Times in 817 Posts
IndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura aboutIndiReloaded has a spectacular aura about
Not a direct answer, but a caution for the unwary:

Nothing you commit to the internet should be considered secure. Emails can be read by system admins, IP addressses can be traced (sometimes), that sort of thing. There are ways to check who's looking (we look periodically to see who has pinged our computers) & its sometimes interesting to see what you find.

Its that old saying: if you don't want to be held accountable for saying it, don't say it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 28-05-08, 06:46 AM
anachronistic
 
Posts: n/a
Words of wisdom from Indi; of course precautions should be taken into consideration. But what I am getting at is even more important; the user login of the forum uses an algorithm of cryptography, called MD5, which is known for its simple vulnerabilities. Its hashes are easily decoded, because they are very simply encrypted. What does this mean? Well, someone that knows what they are doing could phish a page to you, because it is not HTTPS, and get your username and password. They could also retrieve the hash of the username/password and decrypt it, and have access to your account here (and possibly other websites, and more personal information if you use the same password for everything)

As I recall, this has happened already with one account (Dono) and vulnerability remains open.

I am just looking out for this community by examining the issue. Time and time again in my experience as a server specialist and web designer, my opinion is that users tend to use the same username/password for everything. I am informing the public about this, and hopefully they will make any necessary changes, to ensure their security, but it is not guaranteed.

I also think it is the duty of administrative staff, even moderators on forums, to do everything they can, within reasonable boundaries, to eliminate any such problems. Why? Well, that is how the successful websites do it. The mindset of "Pfft, well that's just how the Internet is," is somewhat hindering, because it is, in a way, avoiding a problem. Sure, that's how the Internet is now, but it is not adamant. It can be changed, for the better, or for the worse. I am here to make it for the better, as I see it. Don't you want that? Don't you care?

And from a philosophical point, nothing in this world is secure. Nothing is symmetrical. So this lesson can be applied to actual life, too. I am actually writing about that in my freetime. A life of independence is a perfect one.

Oh, and I want to be recognized for the things I say. Even on here. I take full credit for all of it, but unfortunately, some sneaky bastard will probably take that away from me. Oh well. Hopefully what I said was so cleverly toned and original, that nobody could ever imitate it and call it their own. HA!

Last edited by anachronistic : 28-05-08 at 06:57 AM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 29-05-08, 08:28 PM
Kiechi Kiechi is offline
Moderator
 
Join Date: Apr 2004
Gender: Male
Posts: 4,141
My Mood:
Thanks: 248
Thanked 122 Times in 96 Posts
Kiechi has a spectacular aura aboutKiechi has a spectacular aura aboutKiechi has a spectacular aura about
I don't think anyone really cares to be honest.
__________________
Sick and tired of my condition, this lust, this vampiric addiction, to her alone in submission, sunsetter, Nymphetamine.

http://uk.youtube.com/watch?v=E5_tLjvf4oU
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to Kiechi For This Useful Post:
vashti (10-06-08)
  #7 (permalink)  
Old 29-05-08, 08:54 PM
loveadmin's Avatar
loveadmin loveadmin is offline
Live with passion
 
Join Date: Sep 2001
Gender: Male
Posts: 608
My Mood:
Thanks: 0
Thanked 21 Times in 16 Posts
loveadmin will become famous soon enoughloveadmin will become famous soon enough
Sorry for the late answer. Just to assure everyone that the login is secure.
__________________
Loveadmin
"It is not length of life, but depth of life." -- Ralph Waldo Emerson
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 30-05-08, 10:22 AM
Illusional Illusional is offline
different state of mind
 
Join Date: Sep 2001
Gender: Male
Posts: 12,831
My Mood:
Thanks: 14
Thanked 302 Times in 254 Posts
Illusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the rough
Send a message via ICQ to Illusional Send a message via AIM to Illusional Send a message via MSN to Illusional
yup, i don't really care. that's why i have a million and one passwords.. i have to write everything down to keep track of them. of course i lock them in my safe that has the same combination as my birthday so that i will never forget it. i'm all good.

raverboy
__________________
...this is just my perspective on the situation...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to Illusional For This Useful Post:
Kiechi (04-06-08)
  #9 (permalink)  
Old 04-06-08, 10:07 AM
lesa's Avatar
lesa lesa is offline
Registered User
 
Join Date: Dec 2007
Gender: Female
Posts: 1,221
Thanks: 283
Thanked 305 Times in 243 Posts
lesa will become famous soon enoughlesa will become famous soon enoughlesa will become famous soon enoughlesa will become famous soon enough
Quote:
Originally Posted by Illusional View Post
yup, i don't really care. that's why i have a million and one passwords.. i have to write everything down to keep track of them. of course i lock them in my safe that has the same combination as my birthday so that i will never forget it. i'm all good.

raverboy
lol. Your SO, family, or friends can break into home and get it.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 04-06-08, 04:04 PM
loveadmin's Avatar
loveadmin loveadmin is offline
Live with passion
 
Join Date: Sep 2001
Gender: Male
Posts: 608
My Mood:
Thanks: 0
Thanked 21 Times in 16 Posts
loveadmin will become famous soon enoughloveadmin will become famous soon enough
Quote:
Originally Posted by Illusional View Post
yup, i don't really care. that's why i have a million and one passwords.. i have to write everything down to keep track of them. of course i lock them in my safe that has the same combination as my birthday so that i will never forget it. i'm all good.

raverboy
Just wonder is rboy drunk while writing this?
__________________
Loveadmin
"It is not length of life, but depth of life." -- Ralph Waldo Emerson
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
The Following User Says Thank You to loveadmin For This Useful Post:
lesa (04-06-08)
  #11 (permalink)  
Old 05-06-08, 09:57 AM
Illusional Illusional is offline
different state of mind
 
Join Date: Sep 2001
Gender: Male
Posts: 12,831
My Mood:
Thanks: 14
Thanked 302 Times in 254 Posts
Illusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the rough
Send a message via ICQ to Illusional Send a message via AIM to Illusional Send a message via MSN to Illusional
i probably was drunk when i wrote that. or atleast i thought i was.

raverboy
__________________
...this is just my perspective on the situation...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 06-06-08, 10:14 AM
anachronistic
 
Posts: n/a
I never pictured raverboy as such a paranoid. Tell me, raverboy, do you insert your butt plug every day to keep yourself on your toes?

Anyway, I actually just used md5 to encrypt a user database on a website I am designing; first I encrypt it with md5, and then it is encrypted again with the MySQL encryption. And then the login uses SSL for maximum security.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #13 (permalink)  
Old 07-06-08, 10:34 AM
Illusional Illusional is offline
different state of mind
 
Join Date: Sep 2001
Gender: Male
Posts: 12,831
My Mood:
Thanks: 14
Thanked 302 Times in 254 Posts
Illusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the roughIllusional is a jewel in the rough
Send a message via ICQ to Illusional Send a message via AIM to Illusional Send a message via MSN to Illusional
Quote:
Originally Posted by lilwing View Post
I never pictured raverboy as such a paranoid. Tell me, raverboy, do you insert your butt plug every day to keep yourself on your toes?

Anyway, I actually just used md5 to encrypt a user database on a website I am designing; first I encrypt it with md5, and then it is encrypted again with the MySQL encryption. And then the login uses SSL for maximum security.
paranoid?? i only keep my butt plug in because i'm worried that gay people like you want to stick your thing up my ass.

raverboy
__________________
...this is just my perspective on the situation...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #14 (permalink)  
Old 09-06-08, 10:40 AM
TAVS's Avatar
TAVS TAVS is offline
Moderator
 
Join Date: Jul 2005
Location: Colorado
Posts: 2,409
Thanks: 0
Thanked 4 Times in 3 Posts
TAVS will become famous soon enough
MD5 is definitely secure, but you still have to use a somewhat complex password. If you use the word apple, for example, it wouldnt be that hard to figure out even with md5. But there is one thing to always keep in mind, on any site ask yourself, is someone really going to spend that much time and that much computing power to try and access your account on said site. I can bet nobody is going to put in such effort to get your loveforum pass
__________________
"Oh Lord it's hard to be humble, when you're perfect in every way. I can't wait to look in the mirror, cause I get better loking each day. To know me is to love me, I must be a hell of a man. Oh Lord it's hard to be humble, but I'm doing the best that I can." Mac Davis
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #15 (permalink)  
Old 10-06-08, 10:18 PM
loveadmin's Avatar
loveadmin loveadmin is offline
Live with passion
 
Join Date: Sep 2001
Gender: Male
Posts: 608
My Mood:
Thanks: 0
Thanked 21 Times in 16 Posts
loveadmin will become famous soon enoughloveadmin will become famous soon enough
Quote:
Originally Posted by TAVS View Post
MD5 is definitely secure, but you still have to use a somewhat complex password. If you use the word apple, for example, it wouldnt be that hard to figure out even with md5. But there is one thing to always keep in mind, on any site ask yourself, is someone really going to spend that much time and that much computing power to try and access your account on said site. I can bet nobody is going to put in such effort to get your loveforum pass
TAVS! long time never see you here.

Our server is going move to denver, colorado very soon. I bet you will get a good ping from your home next week onward.
__________________
Loveadmin
"It is not length of life, but depth of life." -- Ralph Waldo Emerson
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Loveforum Breaktime
love

Loveforum also recommend

  • Green tea - Help in weight loss and decrease rate of getting cancer.
Reply


Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Loveforum Gallery loveadmin Announcement 68 18-05-04 08:15 AM
From insecure to secure, my story .. corewarp Off Topic Discussion 2 27-05-02 02:25 PM
Snow at loveforum joseph Off Topic Discussion 0 12-12-01 05:53 PM


All times are GMT +8. The time now is 04:54 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99