Hm... Name + Password combination. I will be in as different user?
Hm... Name + Password combination. I will be in as different user?
Different password. It dosn't let me in. Hm. I will not try typo in name. Not to teach the forum the mistake.
Kroc? Are you there? Look at this problem:
Hm... I may not read any reaction here. Please, contact me at https://wien.rocks/@jokibitzer
“Different password. It dosn't let me in.”
Correct, that is what passwords do 😉
“Look at this problem:”
I am not sure I understand. What is the link “in the generated image”? AFAIK, NoNonsense Forum does not generate any images. Is that a Mastodon thing?
If you have found a bug, the best way to communicate it is the issue tracker on GitHub: https://github.com/Kroc/NoNonsenseForum/issues
Is this forum still secure in 2025?
Thanks :)
@cpcnw probably? But the software is old, so it does not implement all of the most recent advancements. It does not use PHP’s password_hash [1] with a modern hashing standard for passwords, nor does it try to address CSRF in a way possible thanks to modern browser changes [2].
Whether those things are an issue the way you are planning to host NNF, only you can decide.
[1]: https://www.php.net/manual/en/function.password-hash.php
[2]: https://www.alexedwards.net/blog/preventing-csrf-in-go
Your friendly neighbourhood moderators: Kroc, Impressed, Martijn