[TYPO3-project-4-3] t3sec_saltedpw as sysext?

Martin Kutschker masi-no at spam-typo3.org
Fri Apr 24 11:47:44 CEST 2009


Ingmar Schlecht schrieb:
> Hi guys,
> 
> what do you think about making t3sec_saltedpw [1] a sysext enabled by
> default in 4.3 and have it enabled for both FE and BE users by default
> as well?
> 
> I think it would be a good thing to ship with this by default.

Maybe. As it requires transfer of plain-text passwords over the net, you
would need SSL if you don't want to loose more security than you gain.
Furthermore what happens with existing accounts? Can they still log in?

So currently I doubt that enabling this by default is an option.

Masi


More information about the TYPO3-project-4-3 mailing list