Page 1 of 1
Passwords encrytion
Posted: 23 Sep 2021, 15:14
by CIE
Hello,
We have enabled password encryption in the system but we see that the user creation confirmation emails are still sent as plain text. Is there no way to correct this?
Thanks.
Re: Passwords encrytion
Posted: 23 Sep 2021, 15:19
by HSNMSupport
Hi,
the passwords are encrypted at the DB level, but in case you print the user card or send the credentials via email, the password is decrypted.
Have a nice day.
Re: Passwords encrytion
Posted: 23 Sep 2021, 17:02
by CIE
Hello,
But then, what is the use of the option to encrypt the password? it does not imply any type of security. The ideal is to store the passwords irreversibly with some hashing algorithm...
Re: Passwords encrytion
Posted: 23 Sep 2021, 17:07
by HSNMSupport
The idea is to increase security, and if for some reason data are stolen, the passwords are secured and not clear.
Re: Passwords encrytion
Posted: 23 Sep 2021, 17:16
by CIE
The idea is to increase security, and if for some reason data are stolen, the passwords are secured and not clear.
But they can still be stolen when printed or sent
Re: Passwords encrytion
Posted: 23 Sep 2021, 17:19
by HSNMSupport
If you decide to send it via email or SMS, the password is sent in clear and we have nothing that can be done.
Please disable the credentials sending if you require it.