MyBB Tutorials
Using bcrypt on your MyBB forum.
Submitted by cute, 06-08-2015, 01:17 PM, Thread ID: 8621
Thread Closed
RE: Using bcrypt on your MyBB forum.
18-09-2015, 04:51 PMDP_PN Wrote:if you have different passwords everywhere that's not your concern. It would be whether or not someone can authenticate as you, without even knowing your password...17-09-2015, 01:11 AMPulseeey Wrote:16-09-2015, 02:06 PMDP_PN Wrote: The weakness of the password storage method is irrelevant to be honest with you. If you have the hash, that you took from the database, you also have the loginkey. With the loginkey, you can instantly start a session for any user, without using a password.
I would have thought people would be more concerned regarding their (potentially) everyday-use password being known, rather than someone being able to login to their forum account?
If I was made aware that a database was leaked, that contained my everyday password. I wouldn't give 2 fucks about the compromised website, I'd be too busy resetting all the shit that uses that password.
FYI, All of my passwords are different and complex, this is an example.
What's the point of having the password? Isn't it to authenticate? You can bypass the hassle of having to bruteforce millions of combinations by simply using the loginkey. Of course if someone finds out there was a breach, the logout can be forced. It's the same breach people would use to get the password hashes so it would still be possible to alert everyone to change password before you could even use it. A lot of people use the same password for different sites, that's right - and that's the only advantage of getting the password rather than the loginkey.17-09-2015, 01:04 AMNekomimi Wrote:16-09-2015, 02:06 PMDP_PN Wrote: The weakness of the password storage method is irrelevant to be honest with you. If you have the hash, that you took from the database, you also have the loginkey. With the loginkey, you can instantly start a session for any user, without using a password.
Not if you force everyone to logout in the event of a breach.
I'm either really chill, or I'm unusual. I personally wouldn't give a fuck if someone had my login key, I'd be more concerned regarding my passwords (whether they are the same for other sitesor not).
Users browsing this thread: 4 Guest(s)