Private messages encrypted?

Do not post support requests, bug reports or feature requests. Discuss phpBB here. Non-phpBB related discussion goes in General Discussion!
Anti-Spam Guide
Post Reply
thanhmy
Registered User
Posts: 1
Joined: Thu Oct 12, 2017 11:53 am
Contact:

Private messages encrypted?

Post by thanhmy » Thu Oct 12, 2017 12:48 pm

Hi
Quick question - hopefully someone knows...
Are private messages in the phpBB 3 stored in the database encrypted or plain text?
Hello, my name is Myca, nice to meet Everyone. giup viec nha | giúp việc nhà

User avatar
Mick
Support Team Member
Support Team Member
Posts: 18021
Joined: Fri Aug 29, 2008 9:49 am
Location: Cardiff

Re: Private messages encrypted?

Post by Mick » Thu Oct 12, 2017 1:20 pm

Plain text. The only people that can ever see those plain text PM messages are people with access to the database itself.
"The more connected we get the more alone we become" - Kyle Broflovski

There are no ‘threads’ in phpBB, they are topics.
Forza Garibaldi

User avatar
stevemaury
Support Team Member
Support Team Member
Posts: 47892
Joined: Thu Nov 02, 2006 12:21 am
Location: The U.P.
Name: Steve
Contact:

Re: Private messages encrypted?

Post by stevemaury » Mon Oct 16, 2017 5:08 pm

Or their sender and recipient(s).
For REALLY good and VERY inexpensive hosting CLICK HERE

All unsolicited PMs will be ignored.

User avatar
thecoalman
Former Team Member
Posts: 2286
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.

Re: Private messages encrypted?

Post by thecoalman » Sat Oct 21, 2017 6:27 am

...or someone that hacks into the server.

User avatar
AmigoJack
Registered User
Posts: 4946
Joined: Tue Jun 15, 2010 11:33 am
Location: グリーン ヒル ゾーン
Contact:

Re: Private messages encrypted?

Post by AmigoJack » Mon Oct 23, 2017 7:25 am

thecoalman wrote:
Sat Oct 21, 2017 6:27 am
someone that hacks into the server.
No, the database can still reside elsewhere or have its own encryption.
The worst thing about censorship is ███████████

User avatar
thecoalman
Former Team Member
Posts: 2286
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.

Re: Private messages encrypted?

Post by thecoalman » Tue Oct 24, 2017 1:00 am

AmigoJack wrote:
Mon Oct 23, 2017 7:25 am
thecoalman wrote:
Sat Oct 21, 2017 6:27 am
someone that hacks into the server.
No, the database can still reside elsewhere or have its own encryption.
:lol: And how many sites phpBbB will have a setup like that? .0000000009%?

It would protect the database server but If your application server is hacked they have the private key and the credentials for the database server. It's not without merit but certainly no replacement for a system where the private key is held by the user and/or the admin alone.

User avatar
AmigoJack
Registered User
Posts: 4946
Joined: Tue Jun 15, 2010 11:33 am
Location: グリーン ヒル ゾーン
Contact:

Re: Private messages encrypted?

Post by AmigoJack » Tue Oct 24, 2017 6:59 am

Oh, if we want to talk about probability instead of facts I could post even more things to access private messages. My fault.
The worst thing about censorship is ███████████

User avatar
thecoalman
Former Team Member
Posts: 2286
Joined: Wed Dec 22, 2004 3:52 am
Location: Pennsylvania, U.S.A.

Re: Private messages encrypted?

Post by thecoalman » Tue Oct 24, 2017 11:00 am

AmigoJack wrote:
Tue Oct 24, 2017 6:59 am
Oh, if we want to talk about probability instead of facts I could post even more things to access private messages. My fault.
You are arguing in circles. It's not a matter of if they can be protected, it's a matter of implementing it.

Minimally they can be protected using the password as the private key. This would be far from 100% secure but would be better than nothing.

As it is now with crime syndicates and state backed hacking aggregating data from various sources steps that can be taken to protect users data should be taken.

Post Reply

Return to “phpBB Discussion”

Who is online

Users browsing this forum: Tbot [Bot] and 20 guests