<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>aC forum: Password Security</title>
  <link>http://www.activecollab.com/forums/topic/2123/</link>
  <description>Recent posts on topic: Password Security</description>
  <dc:language>en-us</dc:language>
  <pubDate>Mon, 01 Dec 2008 23:32:17 UTC</pubDate>
  
  <item>
    <link>http://www.activecollab.com/forums/post/10119/#post10119</link>
    <guid>http://www.activecollab.com/forums/post/10119/#post10119</guid>
    <title>Post #5 by pdiki</title>
    <dc:creator>pdiki</dc:creator>
    <description><![CDATA[<p>: ) this is very true!<br />
<br />
Cheers, was just a thought. </p>]]></description>
    <pubDate>Wed, 17 Oct 2007 10:37:43 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/10116/#post10116</link>
    <guid>http://www.activecollab.com/forums/post/10116/#post10116</guid>
    <title>Post #4 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>If someone breaks in and gains access to your database you have more serious problems than that.<br />
<br />
We'll see what we can do about password encryption in the future.</p>]]></description>
    <pubDate>Wed, 17 Oct 2007 10:34:28 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/10115/#post10115</link>
    <guid>http://www.activecollab.com/forums/post/10115/#post10115</guid>
    <title>Post #3 by pdiki</title>
    <dc:creator>pdiki</dc:creator>
    <description><![CDATA[<p>Thanks Ilija, <br />
<br />
I was more concerned with someone hacking/browsing the database and seeing a list of passwords. Could the API not use an encypted version?</p>]]></description>
    <pubDate>Wed, 17 Oct 2007 10:24:11 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/10114/#post10114</link>
    <guid>http://www.activecollab.com/forums/post/10114/#post10114</guid>
    <title>Post #2 by Ilija Studen</title>
    <dc:creator>Ilija Studen</dc:creator>
    <description><![CDATA[<p>Decision to store password in plain text format was not related to Forgot password functionality. Passwords need to be accessible through the API so system needs to be able to read them. They are available only if you are accessing the system as administrator, people manager or the user itself.</p>]]></description>
    <pubDate>Wed, 17 Oct 2007 10:14:23 UTC</pubDate>
  </item>
  <item>
    <link>http://www.activecollab.com/forums/post/10113/#post10113</link>
    <guid>http://www.activecollab.com/forums/post/10113/#post10113</guid>
    <title>Post #1 by pdiki</title>
    <dc:creator>pdiki</dc:creator>
    <description><![CDATA[<p>Hi all,<br />
<br />
Just been looking at the activecollab database for my installation, and noticed that the &quot;users&quot; table stores passwords in plain text. Is this not a security issue? I have been led to believe that only encrypted passwords should be stored, i.e. and md5 hash of the password. I know that this makes retrieving the users password impossible but this can easily be overcome by reseting the users password if they have forgotten it.<br />
<br />
Any thoughts?</p>]]></description>
    <pubDate>Wed, 17 Oct 2007 10:07:11 UTC</pubDate>
  </item>
</channel>
</rss>