Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Passwords sent in clear text - no other option?!Passwords sent in clear text - no other option?!
Previous
 
Next
New Post
3/22/2007 1:21 PM
 

Today, when a user requests a password, using the password salt, the now unencrypted password can be emailed back to the user in clear text.   Even though the Microsoft membership model includes functionality to randomly generate a password that could then get sent to the user, DotNetNuke does not provide the interface to it.   Per DNN 4.4.1 documentation, these features are not implemented:

Public Properties ( and default values )

Am I wrong?  

Wouldn't the more secure, and preferrable method of sending a user a password they have forgotten, be to randomly generate them a new password, send them that password, then perhaps force a password change once they log in?

Are there plans to update to a more secure functionality?

passwordAttemptThreshold = 5
passwordAttemptWindow = 10
enablePasswordRetrieval = False
enablePasswordReset = True
requiresQuestionAndAnswer = True
requiresUniqueEmail = True
passwordFormat = Hashed

I essentially can not pass a security audit like this, because this allows me the capability of decoding users passwords...  which is potentially the same password they use on multiple sites... for bank accounts, credit information, etc.etc.
 
New Post
3/22/2007 3:21 PM
 
AFAIR in web.config you can set password to hashed instead of encrypted, and the password sending should stop.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
3/22/2007 3:25 PM
 

Will they still be able to recover a lost password?  I don't understand what hashed will do... 

Thanks for your help.

 
New Post
3/22/2007 3:35 PM
 
a hashed password cannot be recovered and not be resend. you might need to add your own solution to retrieve the password, but AFAIR there has been enhancements in DNN 4.5.0 to allow question and answer as option for password retrieval. Please check the blogs for details.

Cheers from Germany,
Sebastian Leupold

dnnWerk - The DotNetNuke Experts   German Spoken DotNetNuke User Group

Speed up your DNN Websites with TurboDNN
 
New Post
3/22/2007 3:57 PM
 

Hi Sebastian,

Great to hear that the Q&A has been implemted in 4.5. I tried this in 4.3.6 without much succes. Will I be able to introduce the Q&A functionality in an existing 4.4.1 installation after I upgrade to 4.5? Does this also apply for setting encrypting passwords to hashed?

By the way: any idea when 4.5 will be released ;-)

Thanks

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Passwords sent in clear text - no other option?!Passwords sent in clear text - no other option?!


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out