in reply to Re: Ideas for "fixing" PerlMonks 1.0
in thread Ideas for "fixing" PerlMonks 1.0
Having just re-read it, I see what I believe is a way to cut the Gordian knot. It could feel like a large, atomic change is needed to both encrypt the passwords, and put in place the workflow needed to do password resets that would be needed because the plaintext isn't available anymore.
But what about making a workflow for password resets now, even though the passwords are still plaintext in the database? It would both set the conditions for then encrypting the passwords as a second, independent step, and already increase security a bit by not having plaintext passwords be emailed around, and sit in people's mailboxes for ze baddies to snarf up.
|
---|
Replies are listed 'Best First'. | |
---|---|
Re^3: Ideas for "fixing" PerlMonks 1.0
by Arunbear (Prior) on Dec 17, 2024 at 11:32 UTC | |
by etj (Priest) on Dec 18, 2024 at 08:59 UTC | |
by jdporter (Paladin) on Dec 18, 2024 at 14:21 UTC | |
by LanX (Saint) on Dec 18, 2024 at 14:35 UTC | |
by jdporter (Paladin) on Dec 18, 2024 at 17:17 UTC | |
| |
by LanX (Saint) on Dec 18, 2024 at 09:52 UTC | |
by erzuuli (Cannon) on Dec 18, 2024 at 14:18 UTC | |
by LanX (Saint) on Dec 18, 2024 at 14:37 UTC |