RFCM

RFCM discussion => Using the Forum => Topic started by: Administrator on October 04, 2023, 12:20:24 PM

Title: Why did we upgrade RFCM?
Post by: Administrator on October 04, 2023, 12:20:24 PM
After being asked why we upgraded from SMF 2.1 from 2.0, and all the resultant UI queries and comments

The main reasons are


From a my point of view the critical one is PHP v7 is now EOL *end of life. As such there will be no more patches - and there will be pressure from ISPs to stop using applications using php 7 (not yet - but its only a matter of time)

BCRYPT is an improved password-hashing mechanism, to hinder dictionary attacks. As such is a good thing.

Finally, the vulnerability to Cross Site Request Forgery. Again, RFCM stores very little data about users, but this is additional protection against those users who have insufficient protection on their browser side. Technically they could harvest IP addresses from RFCM. This isn't a problem in itself, but can result in a wider attack (geolocation ID and physical robbery or device hacking etc.)

Note-  that none of these are related to UI functional improvements. 

So, when you see 'upgrade' it doesn't always mean its about enriching the user experience. But as in this case its about 'watching your back'

thanks
Simon


Title: Re: Why did we upgrade RFCM?
Post by: martin goddard on October 04, 2023, 12:25:39 PM
Thanks for dong the work Simon. It is appreciated.
The reasons are exactly what I thought they would be(? :-[ )


martin :)
Title: Re: Why did we upgrade RFCM?
Post by: Ben Waterhouse on October 04, 2023, 02:37:07 PM
Thanks Simon, not that I understand three quarters of the words...
Title: Re: Why did we upgrade RFCM?
Post by: Colonel Kilgore on October 04, 2023, 03:39:42 PM
Quote from: Ben Waterhouse on October 04, 2023, 02:37:07 PMThanks Simon, not that I understand three quarters of the words...

I feel sure that, if you buy Simon C a coffee via the button on this Forum [https://www.buymeacoffee.com/rocketsix], he won't hold it against you  :D

Simon
Title: Re: Why did we upgrade RFCM?
Post by: Jimmy James on October 04, 2023, 04:42:04 PM
Also it looks go-fasta, which I think is always a good proportion of the user experience.Lovely job.

Jimmy