Security - forgotten password.

10 years 9 months ago #230657 by 3cellhosting
Security - forgotten password. was created by 3cellhosting
Hi there,

We have a client who has had a security test carried out on their site and one of the defined medium risks was the fact that when a user requests 'Forgotten password' from site the supposedly temporary password is sent via unencrypted email, e.g. cleartext, and could be intercepted and used before the authorised user gets to login and update password. End result is a user locked out of their own account.

Will CB go down the road of sending a link to password change page in the way the Joomla 2.5 default does?

If not, is there any way to secure the email?

Regards

David

David
www.3cellhosting.com - where personality, creativity and integrity come as standard.

Please Log in to join the conversation.

10 years 9 months ago #230682 by beat
Replied by beat on topic Security - forgotten password.
Hi David,

Always good to see security reviews and tests.

Glad to see that only this item concerns CB :-)

Yes, we are implementing a password reset mechanism similar to Joomla 2.5 in upcomming CB 2.0. We will discuss if we should backport this to CB 1.9.

As a general rule, if you have any security-related items, even minor, please use the "Contact" link at bottom of any page for private reporting instead of posting in forum.

Beat - Community Builder Team Member

Before posting on forums: Read FAQ thoroughly -- Help us spend more time coding by helping others in this forum, many thanks :)
CB links: Our membership - CBSubs - Templates - Hosting - Forge - Send me a Private Message (PM) only for private/confidential info
The following user(s) said Thank You: 3cellhosting

Please Log in to join the conversation.

10 years 9 months ago #230683 by 3cellhosting
Replied by 3cellhosting on topic Security - forgotten password.
Hi Beat,

To my mind it was not really a security issue as the email from Joomla could also be intercepted and actioned but that is a one time use. Still the same ultimate risk.

After 1 week of server penetration tests they only came up with 6 medium risks and 8 low risks and 4 information points - 2 of the medium risks can be cured by client having SSL certificate installed. To me that is a great reason for using Joomla and reliable 3rd party extensions such as CB and CB subs. :)

Point taken about real security issues and use of 'contact us' rather than a forum board. B)

David
www.3cellhosting.com - where personality, creativity and integrity come as standard.

Please Log in to join the conversation.

Moderators: beatnantkrileon
Time to create page: 0.209 seconds

Facebook Twitter LinkedIn