phpbb 3.2.7 no backup download radio button

Get help with installation and running phpBB 3.2.x here. Please do not post bug reports, feature requests, or extension related questions here.
User avatar
EA117
Registered User
Posts: 584
Joined: Wed Aug 15, 2018 3:23 am
Contact:

Re: phpbb 3.2.7 no backup download radio button

Post by EA117 » Wed Jun 12, 2019 6:01 pm

Removal of the download link, or an extension to re-enable it, isn't about whether or how recovery from a trashed board will occur.

The change was to make information disclosure, or breach, more difficult than "one click, done."

If someone attains or attempts to misuse administrator backup or founder permission, they can't just "click, now I have 100% of your user information, private communication, and all other database information to peruse at my leisure." Now they would have to compromise the actual hosting account too, in order to attain that level of access.

Yes, the rogue admin still has "lots of access" in phpBB, even without the download link. But now they would need to script something to scrape each and every account information page, and/or each and every public message, over multiple hours or days in order to achieve the same information capture that the "download" link provides in one shot. And they still wouldn't have access to things even founders don't have access to, such as Private Messages, without database access.

microtekblue
Registered User
Posts: 90
Joined: Sat Nov 17, 2007 6:10 am
Location: Ontario, Canada

Re: phpbb 3.2.7 no backup download radio button

Post by microtekblue » Wed Jun 12, 2019 8:50 pm

Lumpy Burgertushie wrote:
Mon Jun 10, 2019 1:53 am
I just tested one of mine. it showed up in the store folder within about 20 seconds. the database is quite small.

is your database very large? the larger the database, the longer it takes to create the backup file.

robert
Thanks for your answer Robert, Yes I think that is the case, as it is a fairly large db now. I was surprised it would take that long, but all good. Thank you.

Post Reply

Return to “[3.2.x] Support Forum”