Decode member passwords
Posted: 04 July 2008 09:42 AM   [ Ignore ]  
Lab Assistant
Avatar
RankRank
Total Posts:  140
Joined  05-13-2006

We are in the process of integrating aMember into an existing EE website.

What’s been discovered is a potential deal breaker: EE stores passwords as SHA1 hash (good) but aMember wants clear text (bad). Security concerns aside, this means existing EE passwords cannot be copied over because aMember desires un-ecoded.

Short of asking members to change their password, is there any way for us to decode the EE passwords for import into aMember?

thanks

geof

 Signature 

Subvert Marketing Inc. - Whitehorse, Yukon, Canada

Profile
 
 
Posted: 04 July 2008 09:58 AM   [ Ignore ]   [ # 1 ]  
Research Scientist
Avatar
RankRankRankRankRankRank
Total Posts:  6557
Joined  04-15-2006

I know this is a Technical Support thread but I have to say that if you do find a way to decode a SHA1 hash then please do let me know as I would be exceptionally rich! wink

All joking aside any system that wants to store users passwords in clear text I would totally 100% stay clear of. If you are dealing with a customer base then you really should be doing everything you can to provide them with a secure environment for their data. Not doing that could open you to some pretty serious charges in certain countries.

That aside as well and the fact that I haven’t used aMember (I know other users here have done so though) I’m just wondering at what stage aMember wants to have a clear text password?

Is this because you already have your site setup and users are already registered and now you want to implement aMember on the site?

If so then I would have thought that there might be a way to get the passwords over to aMember without trying to take years decoding them by maybe simply getting the user to update their password to something new? Don’t know if that is at all a possibility?

I’m just a little astonished that aMember would want the details sent in the clear like that, just really wondering at what stage it needs that. Might help to get users here who already have implemented aMember to understand what is going on and help out on this one.

I remember hearing once though, and this is going back many many years, that it would take a room full of the fastest Cray XMP computers around 700 years or something to even decode one hash so I really think that you might be out of luck on this one if that is what you need to do. wink

Sorry that wasn’t really of any true help but just wanted to see why aMember needs them sent in the clear like that as I was thinking of using it on a site in the near future but if that is the case then I will definitely be steering clear of it.

Hope you get it all sorted soon though.

Best wishes,

Mark

 Signature 

Full List Of Plugins Here!! (16)
 
Retrieve Statuses
Maximum Posts Reached
Neat Link
Redirect
Fetch URI

Profile
 
 
Posted: 04 July 2008 10:05 AM   [ Ignore ]   [ # 2 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  12390
Joined  04-29-2002

Geof, you are correct, there isn’t any other way of doing this other than to request they change their password.

 Signature 

Quick Reference - EE Trial Options - EE Wiki - Docs for updating a build

Profile
MSG
 
 
Posted: 04 July 2008 10:05 AM   [ Ignore ]   [ # 3 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  140
Joined  05-13-2006

Mark,

I would dearly love to stay clear of aMember, but there is no other commercial option for advanced membership management with EE (a desperate plea to EllisLab; please include similar functions in EE v2).

The site is already set up and has been in use for about a year. Member accounts are all in EE but because there’s no auto-expiration feature, aMember must be integrated.

Here’s more details from aMember on clear text passwords.

geof

 Signature 

Subvert Marketing Inc. - Whitehorse, Yukon, Canada

Profile
 
 
Posted: 04 July 2008 11:06 AM   [ Ignore ]   [ # 4 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15380
Joined  05-15-2004
Geof Harries - 04 July 2008 09:42 AM

Short of asking members to change their password, is there any way for us to decode the EE passwords for import into aMember?

Short answer: Sorry, no. This is the point of using a one-way hash function.

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
Posted: 04 July 2008 12:05 PM   [ Ignore ]   [ # 5 ]  
Lab Assistant
Avatar
RankRank
Total Posts:  140
Joined  05-13-2006

Sue and Ingmar - Sorry to hear this isn’t possible. I understand the security concerns, just bummed we now have to go this route. Thanks for your help.

 Signature 

Subvert Marketing Inc. - Whitehorse, Yukon, Canada

Profile
 
 
Posted: 04 July 2008 01:45 PM   [ Ignore ]   [ # 6 ]  
Moderator
Avatar
RankRankRankRankRankRankRank
Total Posts:  15380
Joined  05-15-2004

Sorry I have no other answer for you. Marking this as resolved.

 Signature 

Everything will be good in the end. If it’s not good, it’s not the end.

Profile
MSG
 
 
   
 
 
Post Marker Legend
New Topic New posts Hot Topic Hot Topic with new posts New Poll New Poll Moved Topic Moved Topic Sticky Topic Sticky topic
Old Topic No new posts Hot Old Topic Hot Topic with no new posts Old Poll Old Poll Closed Topic Closed Topic Announcement Announcements
Theme
Change Theme
Visitor Statistics
The most visitors ever was 1149, on July 16, 2007 09:33 AM
Total Registered Members: 64938 Total Logged-in Users: 62
Total Topics: 81908 Total Anonymous Users: 46
Total Replies: 440306 Total Guests: 283
Total Posts: 522214    
Members ( View Memberlist )