Hash&salt user-passwords
Skadate saves user-passwords in plaintext. This is a security flaw: if someone gains access to the database that person can see all those passwords.
I'd suggest that only a salted hash of the password is saved in database ("MD5(CONCAT('mypassword','somesalt'))").
Then also a "reset password"-functionality would be needed, since the originial password cannot be restored from the DB.
See also: http://www.techcrunch.com/2009/12/14/rockyou-hacked/
The passwords encryption has been implemented in SkaDate 8.0.2324
17 comments
-
AdminIrene
(Admin, SkaDate Software)
commented
The 'Hash and Salt user passwords' feature will be added in the next software build.
-
AdminIrene
(Admin, SkaDate Software)
commented
Hello guys,
Yes, we understand the urgency of implementing this feature. And we will add it as soon as we can.
-
Smitty
commented
Newbie is right - unencrypted user passwords are what are being identified as a major problem in the Plenty of Fish hacking. It puts all of us using Skadate in a precarious position knowing that this issue exists and is not resolved. This needs to have top priority as it is not a nice to have feature it is a security requirement.
-
newbie
commented
This is a really important feature that needs to be implemented ASAP. Have you read the latest on plentyoffish.com being hacked? Their user passwords are saved in simple text.
http://business.financialpost.com/2011/01/31/canadian-dating-website-plenty-of-fish-hacked/
-
julien
commented
Hi Irene,
I'm quite disapointed. You said it was planned and 4 months later you haven't done anything about it.
I did acquire the Skadate software but cannot migrate to it.It's a shame you favor some nice to have features over a basic security functionality.
-
AdminIrene
(Admin, SkaDate Software)
commented
Hello Julien,
We hope you enjoyed the holidays :)
No, we haven't added this feature to SkaDate software yet. We will have another discussion with our technical team about its priority and sooner integration.
-
julien
commented
Hi Irene,
Checking on the status.
Has it been added in the latest release yet?
A great 2011 to Skadate team -
AdminIrene
(Admin, SkaDate Software)
commented
Hello Julien,
We understand the importance of this feature implementation. We will add it in one of the upcoming builds. I assume, within 4 months.
-
julien
commented
That's so important that it prevents me from migrating my current site to Skadate. Can you provide a release date so I know if I should be waiting or not?
-
njam
commented
-
sarafina
commented
What is the status of this implementation? Will this be done for the build scheduled to be release end of September?
-
Nisse Pettersson commented
I'm waiting for an update that solves this. Should be free for all users of Skadate software. This is a flaw in the while application
-
Chanoc
commented
Hello Irene,
Just checking if this feature has already been implemented in the latest build? This one is very important.
-
Bimmer
commented
I also agree with this functionality for improved security implemented right away in not the next release but a major fix for release 7.x
This is the one security functionality that is keeping me from buying the skadate software and considering others.
Can we get a commitment from Skadate that this needs to worked on and implemented now instead of a future bulid release? Security of one's website users is of utmost importance.
-
Bob Lauckhart commented
I agree with Njam. Do it like this.
Implement feature like Njam explained, but give us (admin) ability to view/edit a member profile. Now, we can click on 'view member profile' but then admin has to login with member-credentials.. This should go automatically. -
AdminIrene
(Admin, SkaDate Software)
commented
We find this suggestion more than reasonable, so it is set for implementation in one of the future builds.
-
CrazyCrack
commented
Im a web master and its personally I think security are very import. Just like that, Joomla use that kind of system.
Its not a big change but it will raise the security of the script!