Private messages encrypted?

Do not post support requests, bug reports or feature requests. Discuss phpBB here. Non-phpBB related discussion goes in General Discussion!
Scam Warning
Post Reply
thanhmy
Registered User
Posts: 1
Joined: Thu Oct 12, 2017 11:53 am
Contact:

Private messages encrypted?

Post by thanhmy »

Hi
Quick question - hopefully someone knows...
Are private messages in the phpBB 3 stored in the database encrypted or plain text?
Hello, my name is Myca, nice to meet Everyone. giup viec nha | giúp việc nhà
User avatar
Mick
Support Team Member
Support Team Member
Posts: 26505
Joined: Fri Aug 29, 2008 9:49 am

Re: Private messages encrypted?

Post by Mick »

Plain text. The only people that can ever see those plain text PM messages are people with access to the database itself.
  • "The more connected we get the more alone we become" - Kyle Broflovski©
  • "The good news is hell is just the product of a morbid human imagination.
    The bad news is, whatever humans can imagine, they can usually create.
    " - Harmony Cobel
User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 52768
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve
Contact:

Re: Private messages encrypted?

Post by stevemaury »

Or their sender and recipient(s).
I can stop all your spam. I can upgrade or update your Board. PM or email me. (Paid support)
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 5871
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.
Contact:

Re: Private messages encrypted?

Post by thecoalman »

...or someone that hacks into the server.
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison
User avatar
AmigoJack
Registered User
Posts: 6108
Joined: Tue Jun 15, 2010 11:33 am
Location: グリーン ヒル ゾーン
Contact:

Re: Private messages encrypted?

Post by AmigoJack »

thecoalman wrote: Sat Oct 21, 2017 6:27 amsomeone that hacks into the server.
No, the database can still reside elsewhere or have its own encryption.
  • "The problem is probably not my English but you do not want to understand correctly. ... We will not come anybody anyway, nevertheless, it's best to shit this." Affin, 2018-11-20
  • "But this shit is not here for you. You can follow with your. Maybe the question, instead, was for you, who know, so you shoved us how you are." axe70, 2020-10-10
  • "My reaction is not to everyone, especially to you." Raptiye, 2021-02-28
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 5871
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.
Contact:

Re: Private messages encrypted?

Post by thecoalman »

AmigoJack wrote: Mon Oct 23, 2017 7:25 am
thecoalman wrote: Sat Oct 21, 2017 6:27 amsomeone that hacks into the server.
No, the database can still reside elsewhere or have its own encryption.
:lol: And how many sites phpBbB will have a setup like that? .0000000009%?

It would protect the database server but If your application server is hacked they have the private key and the credentials for the database server. It's not without merit but certainly no replacement for a system where the private key is held by the user and/or the admin alone.
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison
User avatar
AmigoJack
Registered User
Posts: 6108
Joined: Tue Jun 15, 2010 11:33 am
Location: グリーン ヒル ゾーン
Contact:

Re: Private messages encrypted?

Post by AmigoJack »

Oh, if we want to talk about probability instead of facts I could post even more things to access private messages. My fault.
  • "The problem is probably not my English but you do not want to understand correctly. ... We will not come anybody anyway, nevertheless, it's best to shit this." Affin, 2018-11-20
  • "But this shit is not here for you. You can follow with your. Maybe the question, instead, was for you, who know, so you shoved us how you are." axe70, 2020-10-10
  • "My reaction is not to everyone, especially to you." Raptiye, 2021-02-28
User avatar
thecoalman
Community Team Member
Community Team Member
Posts: 5871
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.
Contact:

Re: Private messages encrypted?

Post by thecoalman »

AmigoJack wrote: Tue Oct 24, 2017 6:59 am Oh, if we want to talk about probability instead of facts I could post even more things to access private messages. My fault.
You are arguing in circles. It's not a matter of if they can be protected, it's a matter of implementing it.

Minimally they can be protected using the password as the private key. This would be far from 100% secure but would be better than nothing.

As it is now with crime syndicates and state backed hacking aggregating data from various sources steps that can be taken to protect users data should be taken.
“Results! Why, man, I have gotten a lot of results! I have found several thousand things that won’t work.”

Attributed - Thomas Edison
Post Reply

Return to “phpBB Discussion”