latest stable versions: v150827 (changelog)

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Does s2Member store passwords Encrypted??

Home Forums Community Forum Does s2Member store passwords Encrypted??

This topic contains 3 replies, has 2 voices. Last updated by  Eduan 4 years, 6 months ago.

Topic Author Topic
Posted: Friday Jun 29th, 2012 at 12:27 pm #17867

After the recent Tutsplus/Amember fiasco, where thousands of members usernames, email addresses and passwords were stored in cleartext, rather than encryped by the Amember wordpress plugin, which were maliciously hacked and stiolen. I wanted to make sure that this NEVER happens to my membership site.

So the question is, does s2Member store members sensitive data in cleartext or is it encrypted?? I’m pretty sure that I remember reading something, somewhere about it being encrypted but I just want to reinforce my suspicions and make sure that I have “fire insurance” before my house burns down, so to speak.

Thanks!
Matt

List Of Topic Replies

Viewing 3 replies - 1 through 3 (of 3 total)
Author Replies
Author Replies
Posted: Friday Jun 29th, 2012 at 9:03 pm #17898
Eduan
Username: Eduan
Moderator

Hello Matthew,

I’m pretty sure s2Member doesn’t store the passwords, instead WordPress does, and WordPress I believe it encrypts it with the MD5 encryption method.

Hope this answers your question. :)

Posted: Saturday Jun 30th, 2012 at 2:44 am #17908

Eduan, thanks for the reply, but… “pretty sure” and “I believe” are more of opinion statements than facts. Is there anyone who can definitively state the facts? Linkedin has a $5 million dollar lawsuit on their hands for a similar issue and I’m “pretty sure” that sucks for them. I don’t want to be up this same creek EVER, if I can help it. Thanks anyway, though.
-Matt

  • This reply was modified 4 years, 6 months ago by  Matthew Hobbs.
Posted: Saturday Jun 30th, 2012 at 1:03 pm #17972
Eduan
Username: Eduan
Moderator

Hello Matthew,

I understand why you want to make sure.

I once made a post about this in the old forums, but I can’t seem to find it, I do remember I mentioned that s2Member encrypts everything important/private in 2 types of encryption, both very secure.

And I am pretty sure WordPress stores the passwords, s2Member simply adds roles, and functionalities to protect content from or for those roles. Atleast that’s how I understand it.

But I assure you, s2Member is very secure. I have never run into any problems, nor have I seen someone complain. You won’t regret buying it, trust me on that. lol

Hope this helps. :)

Viewing 3 replies - 1 through 3 (of 3 total)

This topic is closed to new replies. Topics with no replies for 2 weeks are closed automatically.

Old Forums (READ-ONLY): The community now lives at WP Sharks™. If you have an s2Member® Pro question, please use our new Support System.

Contacting s2Member: Please use our Support Center for bug reports, pre-sale questions & technical assistance.