vb.org Archive

vb.org Archive (https://vborg.vbsupport.ru/index.php)
-   vB4 General Discussions (https://vborg.vbsupport.ru/forumdisplay.php?f=251)
-   -   Do I need to use HTTPS if I'm only concerned about passwords sent cleartext? (https://vborg.vbsupport.ru/showthread.php?t=290027)

RamdonGhai 11-01-2012 06:19 PM

Do I need to use HTTPS if I'm only concerned about passwords sent cleartext?
 
Greetings vb!

So I wanted to move my vb4 forum over to SSL and am completely ready to do so, but one concern is I want to avoid the numerous unsecured content warnings that users will get because there are a variety of different image hosts on the site (most of which are sent via HTTP)

I do know that vbulletin sends the login passwords as salted hashes, but I am curious of the vulnerabilities of that hash. If I'm mainly worried about passwords getting sniffed/cracked, would I really require HTTPS? Are there any other concerns that I am oblivious to?

Thanks a lot in advance!

Also: Anyone have any experience with this mod: https://vborg.vbsupport.ru/showthread.php?t=288450
I need users to be able to keep their passwords for now

Thunderbird8 11-02-2012 07:36 AM

vBulletin only sends passwords as hashes, as far as I know, it uses JavaScript to hash the password before sending it (the salt is NOT applied, as each user's salt is different, and in order to apply the salt before sending the password, the client would need to know what salt to use). Honestly, I'm not all that concerned with passwords being sent over the clear as hashes, as a decent password will be extremely difficult to brute-force (and not likely worth the effort anyway). And when you consider that many other forum systems actually do send the password in the clear (I think, it's been awhile since I've dealt with anything else), I would think that hashes are good enough, at least for your average website.

As for the mod you've linked, you would not be able to use that while allowing everyone to keep their current passwords, as the very large disclaimer text reads.


All times are GMT. The time now is 04:00 PM.

Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2025, vBulletin Solutions Inc.

X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01105 seconds
  • Memory Usage 1,711KB
  • Queries Executed 10 (?)
More Information
Template Usage:
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_navbar_search
  • (1)printthread
  • (2)printthreadbit
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • showthread
Included Files:
  • ./printthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/class_bbcode_alt.php
  • ./includes/class_bbcode.php
  • ./includes/functions_bigthree.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • printthread_start
  • bbcode_fetch_tags
  • bbcode_create
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • printthread_post
  • printthread_complete