| ||||||||||||
![]() |
![]() |
| | LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
(#16)
|
| Senior Member Posts: 5,915 Join Date: Jun 2005 Location: Cumbria, UK |
07-08-2007, 01:04 PM
I suppose (maybe what you are trying to say) is if they have access to the database to obtain the password, they would have access to the tickets table anyway. Icon Headquarters - Its Elixir - Web2Messenger |
| | |
(#17)
|
| Operations Manager Posts: 5,659 Join Date: Jan 2006 Location: United Kingdom |
07-08-2007, 01:12 PM
Quote:
What everyone has to understand, is that "creating your own password" and remembering it, and then having it hashed is all well and good for (say) a forum where you register yourself. But for years and years, people have preferred that the way eSupport was designed - tickets are raised by e-mail, a password is made for you and you are told that password each time you raise a ticket; as it was the perfect convenience for users and set the standard for a lot of other ticketed support software which operate in this way. I urge you not to be ignorant of this fact and to dismiss our decisions as badly thought out. I have said that we will revisit this decision accordingly. Thank you, -------------------------------------------------------------------
| |
| | |
(#18)
|
(#19)
|
| Senior Member Posts: 5,915 Join Date: Jun 2005 Location: Cumbria, UK |
08-08-2007, 11:14 AM
Ah yes, I didn't think of this side of it when I seen Jamie's reply. Icon Headquarters - Its Elixir - Web2Messenger |
| | |
(#20)
|
| Operations Manager Posts: 5,659 Join Date: Jan 2006 Location: United Kingdom |
08-08-2007, 01:08 PM
Hi Chris, I do understand the point of passwords being encrypted and hashed. You said: "Users generally use the same password over and over again for different services." - refer to my previous reply which describes the atypical situation that eSupport has usually been used in, users not selecting their own passwords and used to receiving their ticket info in each ticket receipt. Sure, this could be randomly generated but then the users who do set their own password by registering on the support website get frustrated having their password reset every time their raise a ticket by e-mail. Quote:
Quote:
-------------------------------------------------------------------
| ||
| | |
(#21)
|
| Senior Member Posts: 5,915 Join Date: Jun 2005 Location: Cumbria, UK |
08-08-2007, 01:16 PM
To add to Jamie's point about decryption, I know that one of the companies that offers this service for older versions of Zend and IonCube said they are 90% complete in making a one for the newer versions of Zend and 60% though one for IonCube. Just shows nothing is unbreakable huh? Icon Headquarters - Its Elixir - Web2Messenger |
| | |
(#22)
|
(#23)
|
| Senior Member Posts: 5,915 Join Date: Jun 2005 Location: Cumbria, UK |
08-08-2007, 02:25 PM
Maybe its time to get a developer (Varun would be best) to look over this. Icon Headquarters - Its Elixir - Web2Messenger |
| | |
(#24)
|
| Chief Operating Officer Posts: 821 Join Date: May 2005 Location: Boise, Idaho |
08-08-2007, 07:44 PM
The fact remains that even if passwords are encrypted in the database it is no more secure than plain text. This is because you would have to store the key in plain sight. If an attacker knows: (algorithm + key) = plain text. -------------------------------------------------------------------
|
| | |
(#25)
|
| Operations Manager Posts: 5,659 Join Date: Jan 2006 Location: United Kingdom |
08-08-2007, 07:48 PM
To reiterate what Ryan said, encryption would be useless. To only secure way of doing this would be through irreversible hashing, which will mean two 'modes' of system to choose between (a big development undertaking). -------------------------------------------------------------------
|
| | |
(#26)
|
(#27)
|
| Operations Manager Posts: 5,659 Join Date: Jan 2006 Location: United Kingdom |
08-08-2007, 08:38 PM
Neal, If you read my replies again you will see on more than one occasion that I have said we are not resisting the request and have aknowledged we need to look at things. -------------------------------------------------------------------
|
| | |
(#28)
|
| Senior Member Posts: 5,915 Join Date: Jun 2005 Location: Cumbria, UK |
08-08-2007, 09:42 PM
Yea, maybe we should all just back off this topic and see what the guys at Kayako come back with when planning for V4 begins. Icon Headquarters - Its Elixir - Web2Messenger |
| | |
(#29)
|
(#30)
|
| Senior Member Posts: 5,915 Join Date: Jun 2005 Location: Cumbria, UK |
09-08-2007, 10:07 AM
Is there really a need to have a dig at Kayako on EVERY possible occassion? Icon Headquarters - Its Elixir - Web2Messenger |
| | |
![]() |
| Tags |
| >, encryption, hashing, password |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Misc / General Autosave feature | mblendinger | Will Implement (V4) | 8 | 19-08-2008 11:45 PM |
| UNKNOWN Live chat -> System -> Record operator online hours | urevised | Feature Requests | 10 | 01-03-2008 03:25 PM |
| UNKNOWN System -> Downloads/Attachments -> Must be stored seperately | NC Software | Feature Requests | 2 | 10-11-2006 11:43 PM |