Re: Issue 64 in domuslink: Keep me logging no more working

8 views
Skip to first unread message

Philippe Carlier

unread,
Jun 15, 2011, 4:37:11 PM6/15/11
to domuslink-developers
Hi Brad,

MD5 is not secure if you want to store a password in a cookie.

I think mcrypt is easy to install ( sudo apt-get install php5-mcrypt).
Perhaps we should ask to to domus users ?

Philipe

Le 15/06/2011 04:05, domu...@googlecode.com a �crit :
>
> Comment #7 on issue 64 by bwsamuels: Keep me logging no more working
> http://code.google.com/p/domuslink/issues/detail?id=64
>
> I tested against a version on my system without the mcrypt but using
> all your changes and it works great!
>
> We'll have to decide if we want to double encrypt the password.
>
> Brad
>

Philippe Carlier

unread,
Jun 15, 2011, 4:39:30 PM6/15/11
to domuslink-developers
I've made a fix on decrypt method

Le 15/06/2011 22:37, Philippe Carlier a �crit :

Brad

unread,
Jun 15, 2011, 6:11:31 PM6/15/11
to domuslink-...@googlegroups.com
The encrypt key needs to be randomly generated per system if we want it secure. Currently, someone could read our code and decrypt it using the key in the method.
i don't disagree with having out more secure but we don't enforce ssl on the web server either so the password is being sent in clear text anyway. Also the password file is only obfuscated with md5sum.
So I'm just trying to make it easier for our users in the time being.

Philippe Carlier

unread,
Jun 16, 2011, 5:43:34 PM6/16/11
to domuslink-...@googlegroups.com
Ok, we will add this feature in a future version (private key store in
config.php)...

Can you commit your changes ?

Le 16/06/2011 00:11, Brad a �crit :

Brad

unread,
Jun 22, 2011, 10:38:36 PM6/22/11
to domuslink-...@googlegroups.com
Will do so soon.

Brad

Philippe Carlier

unread,
Sep 19, 2011, 5:21:04 PM9/19/11
to domuslink-...@googlegroups.com
Hi Brad !
How are you since the last time.

We should go ahead on the fix. This issue is really annoying.

Did you made a fix without mcrypt ?

Philippe


Le 23/06/2011 04:38, Brad a �crit :


> Will do so soon.
>
> Brad

> --
> You received this message because you are subscribed to the Google
> Groups "domuslink-developers" group.
> To view this discussion on the web, visit
> https://groups.google.com/d/msg/domuslink-developers/-/KIdvO1fJv-wJ.
> To post to this group, send an email to
> domuslink-...@googlegroups.com.
> To unsubscribe from this group, send email to
> domuslink-develo...@googlegroups.com.
> For more options, visit this group at
> http://groups.google.com/group/domuslink-developers?hl=en-GB.

Brad

unread,
Sep 19, 2011, 9:45:42 PM9/19/11
to domuslink-...@googlegroups.com
I'm good Philippe. Hope you are well also.

I have a branch with some changes, just been too busy with summer. Another 2 or 3 weeks and I will be back into development. I always wait for the colder weather.

Brad

Brad

unread,
Nov 13, 2011, 3:25:56 PM11/13/11
to domuslink-...@googlegroups.com
Alright, finally getting around to updating and fixing. I just uploaded changes to the fixesfor2.0 branch with changed login remember without the encrypt/decrypt. Take a look and let me know if there are any issues.

Brad
Reply all
Reply to author
Forward
0 new messages