Question Mass Password Reset - temporary password options?

Status
Not open for further replies.

dirtyimpreza

Customer
Hello!

Loving the ability to control password complexity via vBSecurity Pro. This is a great product.

We are probably going to use the mass password reset option to purge a bunch of weak passwords out of the user database. Admin CP > DBTech - vBSecurity > Maintenance

When all the passwords are reset, what are they set to? I recall reading in the product description that it was some random numbers. Isn't this still easily "bruteforce-able" than say a series of letters, numbers, mixed case, and symbols. Is there anyway to reset the passwords to something more complicated?

Lastly, if this isn't an option, how many digits does the plugin reset the numeric password to. I am hoping that it is some kind of long number?

Thanks for the help. Again, I am very pleased with this setup so far.
 
It generates a random number between 0 and 100000000 - it's intended to be changed immediately, and there's currently no way to make a more complex password. However, I'll keep this ticket open and see if I can't change it over the weekend to match the password complexity rules or at least add a few more upper- and lower-case letters.

I'd like to avoid symbols in the new password, as they make the password impossible to copy-paste (depending on the symbol and the email client / OS).
 
Fillip H.-

Thank you for your quick response. I agree that the symbols isn't really a requirement and if it does more harm than good it's probably not needed.

What brought this all about, is that if there are old / unused accounts in the user database that someone never decides to actually use and create a proper password, it may sit there for a long time with the temporary password. I want to be sure this is something difficult for a bot to guess / crack.

Upper case / lowercase letters and numbers should be plenty. That would be awesome if you can get this introduced. I will keep tabs on this thread for sure!
 
I've updated the password reset code to generate a more secure a-zA-Z0-9 15-character length password in Monday's update :)
 
I've updated the password reset code to generate a more secure a-zA-Z0-9 15-character length password in Monday's update :)

Letters / numbers / upper & lowercase and 15 characters! Far exceeded my expectations, this is fantastic.

I'll keep an eye out for the update on Monday. Thank you so much for following up on this and making it happen!
 
Got the latest version installed. Thank you so much.

I'll let you know how the mass password reset goes.

Voted in the vbulletin.org thread 5 stars.
 
Status
Not open for further replies.

Legacy vBSecurity

vBulletin 3.8.x vBulletin 4.x.x
Seller
DragonByte Technologies
Release date
Last update
Total downloads
813
Customer rating
0.00 star(s) 0 ratings
Back
Top