Register Members List Search Today's Posts Mark Forums Read

Reply
 
Mod Options
Increase Cost on bcrypt passwords Details »
Increase Cost on bcrypt passwords
Mod Version: 1.00, by Wayne Luke (Administrator) Wayne Luke is offline
Developer Last Online: Mar 2023 I like it Show Printable Version Email this Page

vB Version: 5.4.2 Rating: (1 vote - 5.00 average) Installs: 5
Released: 05 Apr 2019 Last Update: Never Downloads: 31
Not Supported Additional Files  

Valid for vBulletin 5.4.5 and higher.

As processors get more powerful, the time co-efficient to decode password hashes decreases. With vBulletin 5, you can increase the cost co-efficient so that the time stays the same with more powerful processors. The attached file does this for the default password hashing schema in vBulletin 5.4.5 and higher.

To install, simply upload the XML file into your /core/includes/xml folder. No other settings are needed. The next time your users log in, their passwords will be stored with the increased cost.

Download Now

Only licensed members can download files, Click Here for more information.

Show Your Support

  • To receive notifications regarding updates -> Click to Mark as Installed.
  • This modification may not be copied, reproduced or published elsewhere without author's permission.
Similar Mod
Mod Developer Type Replies Last Post
Mini Mods Secure BCrypt Password Hashing MegaManSec vBulletin 4.x Add-ons 27 07 Jan 2016 13:52

Comments
  #2  
Old 15 Apr 2019, 06:52
DamasGate DamasGate is offline
 
Join Date: Aug 2003
Thank you very much.


If removed in the In the future, Will we face any login problems?


Thanks again
__________________
Engineering Community
Damas Wiki
Reply With Quote
  #3  
Old 16 Apr 2019, 07:19
delicjous's Avatar
delicjous delicjous is offline
 
Join Date: Nov 2014
Thank you.

I upload it to a testforum and there was no change in user-table (token, scheme and secret), datastore 'pwschemes' or passwordhistory. Do this change any data to check if it is working?
__________________
ⓒ by delicjous
Reply With Quote
  #4  
Old 06 Aug 2019, 17:10
Wayne Luke's Avatar
Wayne Luke Wayne Luke is offline
 
Join Date: Jan 2002
Real name: Wayne
After the user's next login, the cost in their password hash will change from 10 to 15. That would be the only data change in the database.
__________________
Wayne Luke
Get started with your own social network. Purchase and download vBulletin today.
Reply With Quote
  #5  
Old 06 Aug 2019, 17:11
Wayne Luke's Avatar
Wayne Luke Wayne Luke is offline
 
Join Date: Jan 2002
Real name: Wayne
Originally Posted by DamasGate View Post
If removed in the In the future, Will we face any login problems?
Users will need to reset their passwords in order to login.
__________________
Wayne Luke
Get started with your own social network. Purchase and download vBulletin today.
Reply With Quote
  #6  
Old 05 Nov 2019, 07:29
delicjous's Avatar
delicjous delicjous is offline
 
Join Date: Nov 2014
Just for information.
I got an error by upgrade to the latest 5.5.6 Alpha as long as I have this file in the core/includes/xml folder (step 19).

Something like "missing error_x phrase"

After delete the pwschemes_xustom file the upgrade run until the complete screen.
__________________
ⓒ by delicjous
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Mod Options

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


New To Site? Need Help?

All times are GMT. The time now is 22:44.

Layout Options | Width: Wide Color: