We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 28042 ☆ A M B ☆
    • 24,524 Posts
    http://it.slashdot.org/article.pl?sid=07/11/20/1914209

    I tried it with mine, and ... there it was. Didn’t even need to open any of the links, it was in the summary of most of them. Kind of scary. tongue
      Studying MODX in the desert - http://sottwell.com
      Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
      Join the Slack Community - http://modx.org
      • 7231
      • 4,205 Posts
      Wow, that is scary shocked

        [font=Verdana]Shane Sponagle | [wiki] Snippet Call Anatomy | MODx Developer Blog | [nettuts] Working With a Content Management Framework: MODx

        Something is happening here, but you don't know what it is.
        Do you, Mr. Jones? - [bob dylan]
        • 14050
        • 788 Posts
        I guess my password is a bit random. Mine didn’t show up when pasting in the hash.
          Jesse R.
          Consider trying something new and extraordinary.
          Illinois Wine

          Have you considered donating to MODx lately?
          Donate now. Every contribution helps.
          • 28042 ☆ A M B ☆
          • 24,524 Posts
          Interesting, quite a number of the comments to that article mentioned using a salt for the hash.

            Studying MODX in the desert - http://sottwell.com
            Tips and Tricks from the MODX Forums and Slack Channels - http://modxcookbook.com
            Join the Slack Community - http://modx.org
            • 6726
            • 7,075 Posts
            Quote from: Jesse at Nov 21, 2007, 08:27 AM
            I guess my password is a bit random. Mine didn’t show up when pasting in the hash.

            Neither did mine tongue

            But it sure is an interresting read !
            You really are never completely safe...

            I know some of the web apps I use have salting on top of MD5, activecollab is one of them...
              .: COO - Commerce Guys - Community Driven Innovation :.


              MODx est l'outil id
              • 4971
              • 964 Posts
              Yes, I read a bunch of stuff yesterday after I read this thread...
              Salt seems to make passwords much safer... and even better passphrases... which I think it is what
              some banks are using now.

              How about to use phpass and bcrypt in 0.9.7 or beyond to make MODx almost bulletproof?
                Website: www.mercologia.com
                MODX Revo Tutorials:  www.modxperience.com

                MODX Professional Partner
                • 22303 MODX Staff
                • 10,725 Posts
                Quote from: charliez at Nov 22, 2007, 10:44 AM

                How about to use phpass and bcrypt in 0.9.7 or beyond to make MODx almost bulletproof?
                The encryption method for passwords in xPDO will be configurable (and automatic for password field "types"), and that will make it so for MODx 0.9.7 and beyond as well. In addition, there will be some better support for using user data directly from external authentication sources and supplementing these "external" users with MODx user data (i.e. no password would be stored locally for "external" users), as well as external profile and/or permission sources, if not in 0.9.7, soon thereafter.
                  • 10226
                  • 412 Posts
                  MD5 is great, and salting is better - and not exactly new, just not implemented much. The problem is that unless strict policies are enforced, people will continue to use simple ’dictionary’ and ’birthday’ passwords. My password policy here on my home domain is better than most banks - although the pass-phrase is catching on, my bank switched over almost a year ago.

                  My main password for almost everything is XXXXXXXXXXXXXXXX - is has lower and upper case, numbers and punctuation. I looks long but it is easy to remember and it actually flows. It is not based on a dictionary word or any relevant personal info smiley