FAQ  •  Register  •  Login

Haypi's password security

<<

jglim

Newbie

Posts: 5

Joined: Fri Jun 25, 2010 7:51 am

Post Fri Jun 25, 2010 7:58 am

Haypi's password security

I am unable to find a "delete account" or "change password" function. Also, i realize the passwords stored in Haypi are not hashed/salted in any way. (there's a resend password function, which shouldn't exist)

If the servers get hacked into, the passwords are in plaintext. Please ensure that passwords are properly stored, and that users can only change passwords.
<<

Sylarius

User avatar

Elite

Posts: 820

Joined: Mon Apr 19, 2010 4:14 pm

Location: New York City, NY

Post Fri Jun 25, 2010 8:09 am

Re: Haypi's password security

General Tab -> Management Button -> Reset Password Button -> Follow the remaining procedures there to change your password.

And there are currently no plans for incorporating a delete account function.
Image
Image
A forum post should be like a skirt. Long enough to cover the subject material, but short enough to keep things interesting.
<<

jglim

Newbie

Posts: 5

Joined: Fri Jun 25, 2010 7:51 am

Post Fri Jun 25, 2010 11:42 am

Re: Haypi's password security

Thank you for your reply, it was helpful. I would suggest this to be included in the FAQs.

However, you have not touched on the topic of password storage security. The fact that i can retrieve my password by submitting my email means the password is not entirely secure (since i can obtain the plaintext version of it).

In the event of someone hacking into the servers, if the passwords were hashed, obtaining them in the original form is difficult. Paired with salts, it is nearly impossible.

Here is an excellent read about password storage. I understand Haypi is operated in PHP but this explains the advantages of hashing and salting very well.

http://www.aspheute.com/english/20040105.asp

thank you once again.
<<

Shadetale

King

Posts: 3057

Joined: Thu May 06, 2010 1:44 am

Location: New York City

Post Fri Jun 25, 2010 11:52 am

Re: Haypi's password security

They are busy people and I doubt they have time to upgrade the password database any time soon
Shadetale wrote:Everyone is entitled to their opinion, no matter how misguided, misinformed, or misunderstood it may be... :/
Former Forum Moderator
Former Expert
<<

jglim

Newbie

Posts: 5

Joined: Fri Jun 25, 2010 7:51 am

Post Fri Jun 25, 2010 12:13 pm

Re: Haypi's password security

strange why security shouldn't be a top priority.
<<

Shadetale

King

Posts: 3057

Joined: Thu May 06, 2010 1:44 am

Location: New York City

Post Fri Jun 25, 2010 12:18 pm

Re: Haypi's password security

Well, nobody really cares that much about Haypi passwords to hack into it I mean seriously, it's just a MMOG
Shadetale wrote:Everyone is entitled to their opinion, no matter how misguided, misinformed, or misunderstood it may be... :/
Former Forum Moderator
Former Expert
<<

jglim

Newbie

Posts: 5

Joined: Fri Jun 25, 2010 7:51 am

Post Sat Jun 26, 2010 5:27 pm

Re: Haypi's password security

Shadetale, it might not be easy to understand as a non-developer, but password security is a fundamental aspect of programming.
<<

Bloodwolf

User avatar

Baron

Posts: 153

Joined: Mon May 17, 2010 5:55 am

Location: Alabama

Post Sat Jun 26, 2010 5:36 pm

Re: Haypi's password security

Shadetale wrote:They are busy people and I doubt they have time to upgrade the password database any time soon

hummm busy ppl with what dont they have like one game and i have not seen anything new since i started playing..
Image
Power To The Pack
<<

Bloodwolf

User avatar

Baron

Posts: 153

Joined: Mon May 17, 2010 5:55 am

Location: Alabama

Post Sat Jun 26, 2010 5:36 pm

Re: Haypi's password security

Bloodwolf wrote:
Shadetale wrote:They are busy people and I doubt they have time to upgrade the password database any time soon

hummm busy ppl with what dont they have like one game and i have not seen anything new since i started playing..

busy ppl my left foot.......
Image
Power To The Pack
<<

Acaellum

User avatar

Baron

Posts: 153

Joined: Fri May 21, 2010 6:19 am

Post Sat Jun 26, 2010 5:37 pm

Re: Haypi's password security

Bloodwolf wrote:
Shadetale wrote:They are busy people and I doubt they have time to upgrade the password database any time soon

hummm busy ppl with what dont they have like one game and i have not seen anything new since i started playing..

did you just start playing this week?? Theres changes to haypi every update!
Image
Next

Return to Suggestions

Who is online

Users browsing this forum: No registered users and 7 guests

Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by ST Software for PTF.