--
You received this message because you are subscribed to the Google Groups "Joomla! CMS Development" group.
To unsubscribe from this group and stop receiving emails from it, send an email to joomla-dev-cm...@googlegroups.com.
To post to this group, send an email to joomla-...@googlegroups.com.
Visit this group at http://groups.google.com/group/joomla-dev-cms.
For more options, visit https://groups.google.com/groups/opt_out.
Please pardon any errors, this message was sent from my iPhone.
To unsubscribe from this group and stop receiving emails from it, send an email to joomla-dev-cms+unsubscribe@googlegroups.com.
To post to this group, send an email to joomla-dev-cms@googlegroups.com.
Visit this group at http://groups.google.com/group/joomla-dev-cms.
For more options, visit https://groups.google.com/groups/opt_out.
I'm not sure that we need to do a 3.3, as long as we let everyone know that 3.5 will require a minimum of 5.3.10, and we make it clear to everyone about the security vulnerability.
To unsubscribe from this group and stop receiving emails from it, send an email to joomla-dev-cms+unsubscribe@googlegroups.com.
To post to this group, send an email to joomla-dev-cms@googlegroups.com.
Visit this group at http://groups.google.com/group/joomla-dev-cms.
For more options, visit https://groups.google.com/groups/opt_out.
What we can agree on is, that we will have to revert the implementation
of bcrypt that went into 3.2.0 and start over with that one.
The minimum required PHP version is set at the beginning of a major series, and cannot be changed for that series. This is not something explicitly stated, and is something that I'm going to work in to the new development strategy.I realize there may be times when there is absolutely no other way to solve an issue, but it's still not something that can be taken lightly. I would say we need unanimous support from the community and the leadership teams in order to make such a change.
--
I disagree. It's the linux users who get PHP 5.3 in their lam
Also many just can't upgrade. My cheap rubbish host is sitting on PHP 5.3.22 and however much I moan at them they refuse to upgrade.
--
You received this message because you are subscribed to a topic in the Google Groups "Joomla! CMS Development" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/joomla-dev-cms/GRlyfBfbMpU/unsubscribe.
To unsubscribe from this group and all of its topics, send an email to joomla-dev-cm...@googlegroups.com.
Why? Because the project didn't promise two stage security. It promised B/C in the 3.x series. Not keeping your promises is the first stage of the end.
Think about it. In what industry do you invest anything in someone that you know cannot keep their word? Internet or otherwise.
Am I right in saying that the password hash and salt we currently
store is not secure enough, or is it that it could be better?
Regards,
Andrew Eddie
--
Is MD5 better than broken Bcrypt?
--
You received this message because you are subscribed to a topic in the Google Groups "Joomla! CMS Development" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/joomla-dev-cms/GRlyfBfbMpU/unsubscribe.
To unsubscribe from this group and all of its topics, send an email to joomla-dev-cm...@googlegroups.com.
However, you'd have to make sure everyone on an older version of the CMS had toupgrade to 3.2.1 before upgrading again (otherwise they miss the
check). I'm not sure if that's possible.
Following a long discussion on https://github.com/joomla/joomla-cms/pull/2555 , proposal has been made to change our minimum required PHP version to 5.3.10 for Joomla 3.2.1+ for multiple security reasons.
Ubunutu 12.04 (latest LTS) has 5.3.10, and both CentOS and Debian have newer stable releases available, normally with newer PHP versions too.
Michael asked to bring that question on this list. Done! :-)
Thoughts ?
Objections ?
Comments ?
Feedbacks ?
Thanks to Siteground I've been able to raise this issue with softaculous and they're looking into changing their scripts but other hosts eg rochen use their own installer scripts that also bypass the joomla installer and its update checks
> The first, b/c of the API within a minor version is non-negotiable.
Sorry, but API already changed. We can either
1) keep it like it is and throw the responsibility of figuring out how to handle 3 different types of passwords to the 3rd party developers
2) break the API again and have database full of broken passwords because of some 3rd party dev didn't know how to deal with the API change (J! 2.5 vs J!3.2.0 vs J!3.2.1)
3) revert JCrypt back to what it was and implement a new API next to it, which is well documented and easy to use
Aye. If it's true that BC was broken between 3.1.5 and 3.2.0 (which I believe from what I read so far), then reverting that and restoring BC is our prime goal now.And from there we can implement a new way which is BC where we offer bcrypt support for PHP 5.3.10 and higher.
--
You received this message because you are subscribed to a topic in the Google Groups "Joomla! CMS Development" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/joomla-dev-cms/GRlyfBfbMpU/unsubscribe.
To unsubscribe from this group and all of its topics, send an email to joomla-dev-cm...@googlegroups.com.
To post to this group, send an email to joomla-...@googlegroups.com.
Visit this group at http://groups.google.com/group/joomla-dev-cms.
For more options, visit https://groups.google.com/groups/opt_out.
Our greatest obligation is to the public who will be visiting and using websites built with Joomla.
> > sp we do not explore something irrealistic. it is not > > an email to joomla-dev-cm...@googlegroups.com <javascript:>.
> > To post to this group, send an email to
> joomla-...@googlegroups.com <javascript:>.
> > Visit this group at
> http://groups.google.com/group/joomla-dev-cms
> <http://groups.google.com/group/joomla-dev-cms>.
> > For more options, visit https://groups.google.com/groups/opt_out
> <https://groups.google.com/groups/opt_out>.
>
--
You received this message because you are subscribed to the Google Groups "Joomla! CMS Development" group.
To unsubscribe from this group and stop receiving emails from it, send an email to joomla-dev-cm...@googlegroups.com.
To post to this group, send an email to joomla-...@googlegroups.com.
Visit this group at http://groups.google.com/group/joomla-dev-cms.
For more options, visit https://groups.google.com/groups/opt_out.
Please pardon any errors, this message was sent from my iPhone.
Now that Joomla 3.2.1 has been released, is there an opportunity to revisit the PHP version (and consequently a bcrypt implementation) for Joomla 3.5? The last post by Bakual indicated that the PLT would be considering this. Has any decision been made?
--
Hi Thomas,
Thanks for the link, that is helpful. I'll actually be at DrupalCamp NJ later this month, so I'll see if I can gather some insight about how that change is being handled and the impact it may have on users.
As you can imagine, one of the big challenges we face is that we are in the middle of a major release cycle, versus Drupal 8 starting the new cycle with different requirements. We need to be very careful not to leave any users stranded, while considering the issues at hand.
Thanks again for your patience and consideration.
Best,
Matt Thomas
@betweenbrain
http://matt-thomas.me/
http://betweenbrain.com/
https://github.com/betweenbrain
Sent from mobile. Please pardon any typos or brevity.
--