We use cookies to improve your experience. No personal information is gathered and we don't serve ads. Cookies Policy.

ExpressionEngine Logo ExpressionEngine
Features Pricing Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University
Log In or Sign Up
Log In Sign Up
ExpressionEngine Logo
Features Pro new Support Find A Developer
Partners Upgrades
Blog Add-Ons Learn
Docs Forums University Blog
  • Home
  • Forums

Strict Passwords

Development and Programming

Michael Witwicki's avatar
Michael Witwicki
115 posts
14 years ago
Michael Witwicki's avatar Michael Witwicki

Hey everyone,

I just had a client ask me, what I consider to be a very obvious and reasonable question which I haven’t run into yet. They are currently undergoing a full security audit of their internal systems and the auditor asked if ExpressionEngine can enforce strict passwords. Having a bit of a experience with security audits in the past, I know this to be a pretty typical question. I didn’t see any addons in Devot-EE, and so I was considering building one myself. I was thinking something which:

  • Allowed users to toggle different strength requirements (upper/lower, alpha/numeric, special characters)
  • Disallow reusing old passwords

However, when looking at the extension hooks available - I didn’t seem to find any that would fire when both:

A. A new user is registered B. A user updates their password information

So my questions are:

  1. Am I just missing something? Do these hooks exist and I am not seeing them?
  2. If not, is this something the EL team would consider adding in a future release?

Seems like a pretty important functionality to have particularly for larger corporate clients who have to endure regular security audits.

Thanks so much!

Michael

       
tidy's avatar
tidy
196 posts
14 years ago
tidy's avatar tidy

I came up against the same thing with a client security audit a while back. I did not find any add-ons for this at the time and it would be great if there was functionality to support password security schemes like this.

You can turn on require secure passwords (which must include an upper and lower char as well as a number) and increase the minimum password length in security and session preferences as a first step.

       

Reply

Sign In To Reply

ExpressionEngine Home Features Pro Contact Version Support
Learn Docs University Forums
Resources Support Add-Ons Partners Blog
Privacy Terms Trademark Use License

Packet Tide owns and develops ExpressionEngine. © Packet Tide, All Rights Reserved.