1
riosoft
Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/5/23 17:12

  • riosoft

  • Not too shy to talk

  • Posts: 191

  • Since: 2003/11/8


...

2
nachenko
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/5/23 17:23

  • nachenko

  • Quite a regular

  • Posts: 356

  • Since: 2005/1/18


Ummm... some bugfixes here and there. The problem editing any users' groups was an important one.

I should try to combine this "personal release" with XOOPS EXM. Better looking and some bugfixes in the same box!

Thanks, Hervé

3
hackbrill
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/5/23 18:35

  • hackbrill

  • Friend of XOOPS

  • Posts: 283

  • Since: 2005/7/14


Thanks for the hard work!

4
costacafj
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 21:10

  • costacafj

  • Just popping in

  • Posts: 3

  • Since: 2004/11/24


Post removed by moderator

Please Note: The original text of this post was posted by someone else then the apparent author.

5
Anonymous
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 21:40

  • Anonymous

  • Posts: 0

  • Since:


Thank you Hervé, and thank you for being so candid about the nature of the release.

Just one thing bothers me....... where does this leave us come the time of an "official" upgrade to the XOOPS core? Will we be able to upgrade from Herve's release to future XOOPS releases or will we have gone down a "fork of no return"?

I don't mean to sound negative as I'm sure that the security improvements are worthwhile and, as always, very welcome. Just thinking ahead a little.....

Either way, thank you Hervé, and good to see your activity - it is much appreciated.

6
skenow
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 22:08

  • skenow

  • Home away from home

  • Posts: 993

  • Since: 2004/11/17


Quote:

JAVesey wrote:

Just one thing bothers me....... where does this leave us come the time of an "official" upgrade to the XOOPS core? Will we be able to upgrade from Herve's release to future XOOPS releases or will we have gone down a "fork of no return"?

I don't mean to sound negative as I'm sure that the security improvements are worthwhile and, as always, very welcome. Just thinking ahead a little.....


From the release notes:
Quote:
WARNING : If you copy the files on an existing version of Xoops, ALL your passwords will be lost and users will have to request a new one. WARNING


Quote:
You should also note that I do not provide ANY support or help or answer for this version. Use it at your own risks. Do not ask some questions on xoops.org or on any other local support site, this is really a personal version



I would only use this for a NEW install, not as an upgrade to an existing site and plan on not upgrading this site.

Best to wait for an official release

7
JMorris
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 23:06

  • JMorris

  • XOOPS is my life!

  • Posts: 2722

  • Since: 2004/4/11


Quote:

JAVesey wrote:
Thank you Hervé, and thank you for being so candid about the nature of the release.

Just one thing bothers me....... where does this leave us come the time of an "official" upgrade to the XOOPS core? Will we be able to upgrade from Herve's release to future XOOPS releases or will we have gone down a "fork of no return"?

I don't mean to sound negative as I'm sure that the security improvements are worthwhile and, as always, very welcome. Just thinking ahead a little.....

Either way, thank you Hervé, and good to see your activity - it is much appreciated.


This Personal Release is not compatible with future versions of XOOPS and will not be supported.

I would strongly encourage anyone who wishes to maintain compatibility with the future versions of XOOPS to NOT use this unsupported version.

Also, there is a patch for most if not all the bugfixes ready on SF.net. If people want to make something useful, they're allowed to test / review the available patches, or even apply them to a 2.0.16 and release some kind of "patched 2.0.16 with bugfixes not yet entirely official"

The big issue with Herve's release is that his password methods do no match what will be used in XOOPS and therefore is dangerous for the average user to implement.
Insanity can be defined as "doing the same thing over and over and expecting different results."

Stupidity is not a crime. Therefore, you are free to go.

8
vaughan
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 23:12

  • vaughan

  • Friend of XOOPS

  • Posts: 680

  • Since: 2005/11/26


i wouldn't say dangerous James.. precarious maybe though :)

9
JMorris
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 23:26

  • JMorris

  • XOOPS is my life!

  • Posts: 2722

  • Since: 2004/4/11


Quote:

vaughan wrote:
i wouldn't say dangerous James.. precarious maybe though :)


Perhaps. The basic gist is that they'll have a tough time moving back to the official branch if they choose to use Herve's version and it is certain their users' passwords will be lost.
Insanity can be defined as "doing the same thing over and over and expecting different results."

Stupidity is not a crime. Therefore, you are free to go.

10
vaughan
Re: Xoops 2.0.17 released (Unofficial version) by Hervé
  • 2007/6/2 23:35

  • vaughan

  • Friend of XOOPS

  • Posts: 680

  • Since: 2005/11/26


that's true.

i'm not even entirely convinced that the changes made to the password are fully necessary anyway. yes sha1 is better encryption but has been cracked aswell as md5. whirlpool would be an even better choice being 512bit encryption.

but that's not the issue really, the hash's are in the db, so the best logical solution to protecting those hash's would be to prevent those hash's being retrieved by unauthorised users, to do that you have to secure the system better to prevent hash's being retrieved either by sql injection or whatever. prevention is better than cure. that's my opinion. but best left for another topic.. lol

Login

Who's Online

180 user(s) are online (113 user(s) are browsing Support Forums)


Members: 0


Guests: 180


more...

Donat-O-Meter

Stats
Goal: $100.00
Due Date: Mar 31
Gross Amount: $0.00
Net Balance: $0.00
Left to go: $100.00
Make donations with PayPal!

Latest GitHub Commits