<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 12 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
        {font-family:Consolas;
        panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
        {mso-style-priority:99;
        mso-style-link:"Plain Text Char";
        margin:0cm;
        margin-bottom:.0001pt;
        font-size:10.5pt;
        font-family:Consolas;}
span.PlainTextChar
        {mso-style-name:"Plain Text Char";
        mso-style-priority:99;
        mso-style-link:"Plain Text";
        font-family:Consolas;}
.MsoChpDefault
        {mso-style-type:export-only;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=EN-AU link=blue vlink=purple><div class=WordSection1><p class=MsoPlainText><span style='font-size:11.0pt;font-family:"Calibri","sans-serif"'>Yes but cryptographically that is not the whole picture. It's using a random salt (for rainbow and dictionary attacks) and what looks like a variant of the 'expensive key schedule' used in <a href="http://en.wikipedia.org/wiki/Bcrypt">EksBlowfish</a> (for brute force attacks). I’m sure it could be characterised in greater detail but I’m not an expert on these matters!<o:p></o:p></span></p><p class=MsoPlainText><span style='font-size:11.0pt;font-family:"Calibri","sans-serif"'><o:p> </o:p></span></p><p class=MsoNormal>Mark<o:p></o:p></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoNormal><b><span style='color:#C50B45'>Mark Gregson</span></b><b> </b>| Applications and Development Team Leader<br><span style='color:gray'>Library eServices | Queensland University of Technology<br>Level 3 | R Block | Kelvin Grove Campus | GPO Box 2434 | Brisbane 4001<br>Phone: +61 7 3138 3782 | Web:</span><span style='color:#A3A3A3'> </span><u><span style='color:#0000FD'><a href="http://www.qut.edu.au/">http://eprints.qut.edu.au/</a><br></span></u><span style='color:#0080FF'>ABN: 83 791 724 622<br>CRICOS No: 00213J<o:p></o:p></span></p><p class=MsoNormal><o:p> </o:p></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText><span lang=EN-US>-----Original Message-----<br>From: eprints-tech-bounces@ecs.soton.ac.uk [mailto:eprints-tech-bounces@ecs.soton.ac.uk] On Behalf Of Dimitrakakis Georgios<br>Sent: Wednesday, 13 March 2013 12:12 AM<br>To: eprints-tech@ecs.soton.ac.uk<br>Subject: [EP-tech] Re: Password Encryption</span></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText>So if I understand correctly it encrypts the passwords using the<o:p></o:p></p><p class=MsoPlainText>SHA512 algorith, right?<o:p></o:p></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText>G.<o:p></o:p></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText>> Dimitrakakis Georgios wrote:<o:p></o:p></p><p class=MsoPlainText>>> Could someone point me to the right place in order to find the way in <o:p></o:p></p><p class=MsoPlainText>>> which user passwords are encrypted in the database using EPrints?<o:p></o:p></p><p class=MsoPlainText>><o:p> </o:p></p><p class=MsoPlainText>> look at EPrints::Utils::crypt()<o:p></o:p></p><p class=MsoPlainText>> <a href="https://github.com/eprints/eprints/blob/master/perl_lib/EPrints/Utils"><span style='color:windowtext;text-decoration:none'>https://github.com/eprints/eprints/blob/master/perl_lib/EPrints/Utils</span></a>.<o:p></o:p></p><p class=MsoPlainText>> pm#L953<o:p></o:p></p><p class=MsoPlainText>><o:p> </o:p></p><p class=MsoPlainText>> ciao<o:p></o:p></p><p class=MsoPlainText>><o:p> </o:p></p><p class=MsoPlainText>> --<o:p></o:p></p><p class=MsoPlainText>> raffaele<o:p></o:p></p><p class=MsoPlainText>> *** Options: <o:p></o:p></p><p class=MsoPlainText>> <a href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech"><span style='color:windowtext;text-decoration:none'>http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech</span></a><o:p></o:p></p><p class=MsoPlainText>> *** Archive: <a href="http://www.eprints.org/tech.php/"><span style='color:windowtext;text-decoration:none'>http://www.eprints.org/tech.php/</span></a><o:p></o:p></p><p class=MsoPlainText>> *** EPrints community wiki: <a href="http://wiki.eprints.org/"><span style='color:windowtext;text-decoration:none'>http://wiki.eprints.org/</span></a><o:p></o:p></p><p class=MsoPlainText>><o:p> </o:p></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText>----------------------------------------------------------------<o:p></o:p></p><p class=MsoPlainText>This message was sent using IMP, the Internet Messaging Program.<o:p></o:p></p><p class=MsoPlainText><o:p> </o:p></p><p class=MsoPlainText>*** Options: <a href="http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech"><span style='color:windowtext;text-decoration:none'>http://mailman.ecs.soton.ac.uk/mailman/listinfo/eprints-tech</span></a><o:p></o:p></p><p class=MsoPlainText>*** Archive: <a href="http://www.eprints.org/tech.php/"><span style='color:windowtext;text-decoration:none'>http://www.eprints.org/tech.php/</span></a><o:p></o:p></p><p class=MsoPlainText>*** EPrints community wiki: <a href="http://wiki.eprints.org/"><span style='color:windowtext;text-decoration:none'>http://wiki.eprints.org/</span></a><o:p></o:p></p></div></body></html>