LocksmithCommunity.com

Nickname:   
Password:   
   
Toggle Content Community ForumsDownloadsWeblinksRegister Wed May 23, 2012 06:30 AM
Toggle ContentMain Menu
 Community Members options Forums Search
Toggle ContentUser Info

Welcome Anonymous

Nickname

Membership:
Latest: RLCML
New Today: 0
New Yesterday: 0
Overall: 1291

People Online:
Members: 1
Visitors: 1
Bots: 2
Staff: 0
Staff Online:

No staff members are online!
Toggle ContentAssoc. / Sponsors
ALOA
Current Location:  Discussion Forums > > PUBLIC FORUMS > > PUBLIC NEWS (Read Only) > > IL password concerns
DL Services
IL password concerns
News / Announcements for the general public (read only)
Post new topic Reply to topic Printer Friendly Page
View previous topic :: View next topic
Author Message
Stubbs
Staff - Administrator
Staff - Administrator

Stubbs

Kyle Stubbins, CMS
Stubb Safe & Vault, Inc.
Hamilton, Ontario
Location: Canada

Joined: Oct 20, 2001
Posts: 4781

Post Post subject: IL password concerns
Posted: Sat Mar 10, 2007 09:26 PM
Reply with quote

I would like to address a comment that I read from a concerned IL member;

Quote::
My user name and password from here worked at the other site.

I believe there was another that I read somewhere that was a little more in depth about the passwords here and on IL. Let me explain how our passwords work.

When you sign up, you give our system a password that you would like to use. When you do so, your password, which is simply a string of characters, gets encrypted with MD5 encryption (Message Digest Algorithm 5 - a 128 bit encryption method) and stored in our database. What does this mean? Your password gets turned into a large string of characters which represents your password.

For example, if I entered the password t14_6eb89Q, it would be turned into an MD5 hash of a8134bc66d0864b37bf55b40b7384691. This hash is ONE WAY ENCRYPTION and cannot be decrypted. Sure, there are sites out there that claim to have MD5 decryption scripts... but they are database based... meaning someone has typed words in and placed the word and corresponding MD5 hash into a database... unless you have typed that particular string into the MD5 encryption of that site, it will not be decrypted... that's how they get the database, from you!

So, how do we verify your password? Easy. When you log in, you type in your password, the site converts it to an MD5 hash and compares it to your MD5 hash already stored in our database. Your password is never revealed to us in plain text.

So, what happens when you retrieve a lost password? Well, you can't retrieve a lost password... we don't know it! Remember? Smile A new password is automatically generated by our system, sent to you and then MD5 hashed. This means that we cannot retrieve your password here and use it to access IL.

Think about it... that works both ways. If it was possible for me to retrieve passwords and go to IL, it would be possible for IL to retrieve passwords and come here, posing as someone else. If I thought that could happen, all of our passwords would have been changed here.


_________________
-= Locksmiths Helping Locksmiths =-

I don’t know what the key to success is,
but the key to failure is trying to please everyone.
Back to top
Offline  View user's profile Send e-mail Visit poster's website MSN Messenger Yahoo Messenger
Stubbs
Staff - Administrator
Staff - Administrator

Stubbs

Kyle Stubbins, CMS
Stubb Safe & Vault, Inc.
Hamilton, Ontario
Location: Canada

Joined: Oct 20, 2001
Posts: 4781

Post Post subject: IL password concerns
Posted: Mon May 07, 2007 11:50 AM
Reply with quote

I am bumping this post as it has been brought to my attention that there are some still whining over on IL that we are using their passwords -- I would like to emphasize (again) the fact that passwords stored in our (or IL's) system CANNOT be retrieved.

I would like to remind you of the "password swapping" that has been going on at IL for over a year -- passwords have been exchanged by the same 4 or 5 people that appear to be running the site as of late -- do a search on IL -- there are posts there to support what I say.

If you think that passwords can be retrieved, first you are misinformed (please read my first post above) and second, that works both ways -- think about it -- if it were possible, it would be pretty easy for the "new administration at IL" to retrieve your password to make it look like LC was doing it.

When "the mob" has no legitimate or legal arguments, I guess they have to start reaching...

If any IL member wishes to confirm anything that I have written here, please feel free to contact the lead developer of the Dragonfly Content Management System (http://dragonflycms.org). You don't have to take MY word for it -- there are a ton of Dragonflycms related sites that you could post on to ask this question.


_________________
-= Locksmiths Helping Locksmiths =-

I don’t know what the key to success is,
but the key to failure is trying to please everyone.
Back to top
Offline  View user's profile Send e-mail Visit poster's website MSN Messenger Yahoo Messenger
Post new topic Reply to topic Printer Friendly Page
You cannot post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You can vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum



You can syndicate our news using the file rss/news.php for RSS V0.91 or rss/news2.php for RSS V2.0
-- LocksmithCommunity.com © 2007-2008 --

This site silently redirects all traffic through the main domain (no www.)


Interactive software released under GNU GPL, Code Credits, Privacy Policy