[TYPO3-project-4-3] saltedpasswords for v4.3

Ingmar Schlecht ingmar at typo3.org
Tue Jul 21 11:30:05 CEST 2009


Hi guys,

Steffen Ritter schrieb:
> In a discussion with Steffen via Skype we turned out that
> saltedpasswords was not activated for be, since he does not use rsaauth.
> 
> Marcus Krause and me once decided not to allow plain transmit of
> BE-Passwords, which would be needed for saltedpasswords without RSA.

I think plain text password transmitted over the wire should be allowed,
because that is actually still a good way when using HTTPS.

cheers
Ingmar


More information about the TYPO3-project-4-3 mailing list