Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Erik Svendsen
Hello Dmitry, > Hi! > > Erik Svendsen wrote: > >> Else md5 hashes are going to be a part of TYPO3 4.3 frontend >> password, together with OpenID both in FE and BE-login. I have also >> suggested to set default min character length both for FE and BE >> password (may be overriden by the admin). T

Re: [TYPO3-english] Limit some accounts to FE only

2008-11-16 Thread Michael H?ügelschä?ffer
Hi, > is there a way to limit some user accounts to FE? I read somewhere that > frontend_edit_only is not compatible with the current release of T3 and > the amount of postings in the newsgroup show similiar results. you may simply redirect an User to FE at login using auth.BE.redirectToURL in

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Andreas Becker
Passwords forth and back As long as TYPO3 stores user data on different places, as long as xtimes personal data get stored on xdifferent places and no coordination takes place at all - TYPO3 will always be not so userfriendly and that is a pitty. There is so much coordination going on why nobody s

Re: [TYPO3-english] official pronunciation of TYPO3

2008-11-16 Thread Andreas Burg
Hello Sebastian, > Listen to the podcasts. There they say it from time to time. I think in > phonetic you write [tai'po:'ðri:]. I know you're German so in German > pronounciation "taiposrie", where the "s" has to be spoken as "th". yes, that's the way I pronounce it too. But I've heard it with

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Sebastian Gebhard
Xavier Perseguers schrieb: > Steffen Gebert wrote: >> Robert Lemke wrote: Yes, I have! It's easy! Just sit down and think out a system for your new passwords - e.g. >>> Better not. I've seen pigs fly ... >> >> Of course nothing is 100% secure.. but it's IMHO much better than >> one-for-a

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Peter Russ
--- Original Nachricht --- Absender: Dmitry Dulepov Datum: 16.11.2008 22:59: > Hi! > > Peter Russ wrote: >> OpenID will help? Really? >> One central place for any access? >> So why is anyone worrying about that TYPO3 got hacked? >> MS or Google will support OpenID. >> So how secure is your

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Marcus Krause
Peter Russ schrieb: > --- Original Nachricht --- > Absender: Dmitry Dulepov > Datum: 16.11.2008 21:29: > [...] >> Firsts, OpenID is different, it has nothing to do with md5. It is >> integrated to 4.3 and it is as secure as your DNS is secure and >> OpenID provider is secure. > > What's ab

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Dmitry Dulepov
Hi! Peter Russ wrote: > OpenID will help? Really? > One central place for any access? > So why is anyone worrying about that TYPO3 got hacked? > MS or Google will support OpenID. > So how secure is your real privacy in reality ;-) > As Google is offering nothing for "free" your will get at least >

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Dmitry Dulepov
Hi! Peter Russ wrote: > What's about all the DNS trouble this year? Not only... If your OpenID looks like http://myopenid.openidprovider.com/ and the attacker manages to override DNS on your network to send all requests for myopenid.openidprovider.com to his own server, he can spoof the identidy

Re: [TYPO3-english] official pronunciation of TYPO3

2008-11-16 Thread Sebastian Gebhard
Andreas Burg schrieb: > Hello, > > does someone knew the official pronunciation of "TYPO3"? > > Andreas Listen to the podcasts. There they say it from time to time. I think in phonetic you write [tai'po:'ðri:]. I know you're German so in German pronounciation "taiposrie", where the "s" has to

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Peter Russ
--- Original Nachricht --- Absender: Dmitry Dulepov Datum: 16.11.2008 21:29: [...] > Firsts, OpenID is different, it has nothing to do with md5. It is > integrated to 4.3 and it is as secure as your DNS is secure and > OpenID provider is secure. What's about all the DNS trouble this year?

Re: [TYPO3-english] Test your TS skills and train for certification

2008-11-16 Thread Sebastian Gebhard
Andreas Burg schrieb: > Ooops, sorry, wrong language, here's the right one. > > Hello Sebastian, > > I've tryed to register and I'm sure having typed same password twice, > but following error occurs. > > "You must enter the same password twice. > > Please enter a password!" > Password looks s

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Peter Russ
--- Original Nachricht --- Absender: stefano cecere Datum: 14.11.2008 16:13: [...] > note: last week someone cloned my bancomat.. i investigated and today > they can sniff password very easily. > like Robert says.. OpenID will help.. maybe also all those security > guidelines that are aro

[TYPO3-english] official pronunciation of TYPO3

2008-11-16 Thread Andreas Burg
Hello, does someone knew the official pronunciation of "TYPO3"? Andreas ___ TYPO3-english mailing list TYPO3-english@lists.netfielders.de http://lists.netfielders.de/cgi-bin/mailman/listinfo/typo3-english

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Dmitry Dulepov
Hi! Erik Svendsen wrote: > Else md5 hashes are going to be a part of TYPO3 4.3 frontend password, > together with OpenID both in FE and BE-login. I have also suggested to > set default min character length both for FE and BE password (may be > overriden by the admin). The md5 hash solution should

Re: [TYPO3-english] Test your TS skills and train for certification

2008-11-16 Thread Andreas Burg
Ooops, sorry, wrong language, here's the right one. Hello Sebastian, I've tryed to register and I'm sure having typed same password twice, but following error occurs. "You must enter the same password twice. Please enter a password!" Password looks similar to this: Ö^2?ÐáÁ?ÝL???»§Ë?̝U Andrea

Re: [TYPO3-english] Test your TS skills and train for certification

2008-11-16 Thread Andreas Burg
Hallo Sebastian, ich wollte mich registrieren und bin mir sicher, dass ich 2mal das gleiche Passwort eingegeben habe, aber es kam eine Fehlermeldung diesbezüglich. "You must enter the same password twice. Please enter a password!" Das Passwort sah ungefähr so aus: Ö^2?ÐáÁ?ÝL???»§Ë?̝U Andrea

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Erik Svendsen
Hello Ries, >> But my point, as an comment on Andreas alligation about unsecure >> TYPO3, is >> that password hashing is only a small part of making a website >> secure and >> has a little to do with the overall security of a CMS or a website. > Yes, that is absolutely right, each part of added

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread ries van Twisk
On Nov 16, 2008, at 10:37 AM, Erik Svendsen wrote: > Hello Ries, > > I drop the quoting. > > I don't think we are disagreeing in any part, I more and less onlys > use md5 > hash and with 7 character as minimum password length on websites, > and would > like to se this as default TYPO3 behavio

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Erik Svendsen
Hello Ries, I drop the quoting. I don't think we are disagreeing in any part, I more and less onlys use md5 hash and with 7 character as minimum password length on websites, and would like to se this as default TYPO3 behavior. And about password length, its ekstremly large amount of users hav

Re: [TYPO3-english] Security subscription in Thunderbird?

2008-11-16 Thread Marcus Krause
Styrmir Magnússon schrieb: > Hello > > But this is what you should read to know that you have to update some of > the extensions. On the homepage this is recommended: > > "We also recommend that you subscribe to the TYPO3 Announce List to > receive all future security bulletins and other importan

Re: [TYPO3-english] Security subscription in Thunderbird?

2008-11-16 Thread Styrmir Magnússon
Hello But this is what you should read to know that you have to update some of the extensions. On the homepage this is recommended: "We also recommend that you subscribe to the TYPO3 Announce List to receive all future security bulletins and other important TYPO3 news." So maybe it is this Ann

Re: [TYPO3-english] Security subscription in Thunderbird?

2008-11-16 Thread Marcus Krause
Styrmir Magnússon schrieb: > Hello list > > I am using Thunderbird to subscribe to some of the news lists regarding > TYPO3, but I don't seem to find out how I can subscribe to the Security > list. Is this possible? The security list is intended to be read by TYPO3 Security Team members only and

[TYPO3-english] Security subscription in Thunderbird?

2008-11-16 Thread Styrmir Magnússon
Hello list I am using Thunderbird to subscribe to some of the news lists regarding TYPO3, but I don't seem to find out how I can subscribe to the Security list. Is this possible? Best regards, Styrmir Magnusson ___ TYPO3-english mailing list TYPO3-eng

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread ries van Twisk
On Nov 16, 2008, at 7:58 AM, Erik Svendsen wrote: > Hello Dmitry, > > You have my support! > > For instance, md5 hash aren't secure at all. Every md5 hashed > password with > less than 6 - 7 characters are unsecure (the hash -> password is > known). Don't forget that some people do have long

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Erik Svendsen
Hello Dmitry, You have my support! For instance, md5 hash aren't secure at all. Every md5 hashed password with less than 6 - 7 characters are unsecure (the hash -> password is known). Security is much more than hashing of password, as long as information is sent in plaintext you can't talk abou

Re: [TYPO3-english] Riedirects in RealURL when changing the name of a section

2008-11-16 Thread Dmitry Dulepov
Hi! Ron Hall wrote: > If I change the name of of a subpage like "Page 3" to "New Page 3" then > RealURL will make a new ID-to-path mapping the reflects the new name and > also set the old path to "expired" which will send a permanent redirect > response if someone hits the old url. This is fine C

Re: [TYPO3-english] TYPO3.ORG hacked

2008-11-16 Thread Dmitry Dulepov
Hi! Andreas Becker wrote: > Simply make the highest standards of security the TYPO3 standard and don't > ask if someone wants a less secure one. If they want to change it to > unsecure it will be their fault if they get hacked and not the one of an > insecure TYPO3. What I dislike in such posts i

[TYPO3-english] Image handling functions

2008-11-16 Thread Tapio Markula
Hi If I want to develop dynamic template (php-file), which uses backend functions, what functions to use * get image by name (image field has the name of the file) * scale image and save it ___ TYPO3-english mailing list TYPO3-english@lists.netfielders.