1
Bugs and Suggestions / Re: HTTPS?
« on: November 22, 2019, 12:02:04 AM »
I mean, to start with, nearly all (if not all) forum softwares were extremely poorly secured until 2015 or so to my knowledge. IIRC, all our passwords are currently stored as MD5 hashes in SMF's database... either that or SHA-1. And we both know that from a security standpoint, those are fucking worthless. But considering that this is the database we have, short of cracking every password longer than 8-9 characters alongside using a rainbow table, we're stuck with those low-level hashed passwords.
Our email system is down too, for reasons I don't understand, so there's no way to force everyone to update their password either, and I don't think this would be a trivial task to fix. Again, someone said they would help fix that and then never showed up again.
It's also pretty safe at this point to assume the database has been breached several times since the creation of this forum.
I welcome anyone else pitching in their ideas, but I'm already in debt because of my health, and this community has grown so thin over the years because everyone who has a lot of experience with FFT modding either left because they hate admins' faces, are too busy with irl/health stuff, or just left/became inactive because we've grown too thin. I don't think a funding project would be successful because as it is, all of the most active people on FFH cannot contribute monetarily.
Our email system is down too, for reasons I don't understand, so there's no way to force everyone to update their password either, and I don't think this would be a trivial task to fix. Again, someone said they would help fix that and then never showed up again.
It's also pretty safe at this point to assume the database has been breached several times since the creation of this forum.
I welcome anyone else pitching in their ideas, but I'm already in debt because of my health, and this community has grown so thin over the years because everyone who has a lot of experience with FFT modding either left because they hate admins' faces, are too busy with irl/health stuff, or just left/became inactive because we've grown too thin. I don't think a funding project would be successful because as it is, all of the most active people on FFH cannot contribute monetarily.