Security Issues

Status
Not open for further replies.

David Mactaggart

Gold Partner
Advanced Certified
Joined
Jun 19, 2015
Messages
9
Reaction score
0
Hello,

Can you let me know if there is any plans to increase the security of the system. Currently if you have access to a backup of 3CX you can gain the passwords used for everything. Are you planning on adding encryption to the backups or anything that would make this inaccessible without a password?

Thanks,
David
 
Hi,

I would suggest to use correct Folder Permissions - so noone can access Backup Folders except Users which are allowed to.
Apart from the fact that only Persons which are allowed have access to the PBX should be able to log into that System.

Andreas Schnederle-Wagner
 
That is fine but you still shouldn't be able to access all passwords from an XML file in an unencrypted ZIP file
 
In the past, some users, having forgotten their password, (I know, I know), have had to resort to recovering it from the backup, so in those cases, it's a good thing that it wasn't encrypted.

Personally, I think that asking 3CX to encrypt the backup file , is simply removing the responsibility from the users, to ensure security of their own system/files. You could submit a Feature Suggestion, of an option, to allow password protection of the zip file... http://www.3cx.com/forums/3cx-ideas-f57.html
 
leejor said:
In the past, some users, having forgotten their password, (I know, I know), have had to resort to recovering it from the backup, so in those cases, it's a good thing that it wasn't encrypted.

Personally, I think that asking 3CX to encrypt the backup file , is simply removing the responsibility from the users, to ensure security of their own system/files. You could submit a Feature Suggestion, of an option, to allow password protection of the zip file... http://www.3cx.com/forums/3cx-ideas-f57.html

It's not about removing responsibility from the user but no decent program will store passwords in plain text anywhere, I will raise it on the ideas page though
 
Status
Not open for further replies.