Tips and Tricks HQ Support

Support site for Tips and Tricks HQ premium products

  • Home
  • Contact Us
  • Documentation
  • Forum Home
    • Forum
    • Forum Search
    • Forum Login
    • Forum Registration

Password encryption and storage in eMember

by

Tips and Tricks HQ Support Portal › Forums › WP eMember › WP eMember General Questions › Password encryption and storage in eMember

Tagged: no password, password, password encryption

  • This topic has 9 replies, 2 voices, and was last updated 9 years, 8 months ago by wzp.
Viewing 10 posts - 1 through 10 (of 10 total)
  • Author
    Posts
  • February 4, 2016 at 2:37 pm #13083
    fourstar
    Member

    We have a member that was appalled to see his password in clear text in an email and left our membership site because of it. I have altered that email AND the ‘change password’ email to remove the password but I’d like to be able to explain to him how it all works behind the scenes. Can you help?

    February 4, 2016 at 2:41 pm #72470
    wzp
    Moderator

    The passwords are kept using a ONE WAY hash. So you can’t look at the database and get passwords (this is the best security practice for storing passwords).

    The following documentation of WordPress has explanation on how passwords are hashed in teh WP system. We use that same functionality in our WP eMember plugin also:

    https://codex.wordpress.org/Function_Reference/wp_hash_password

    What evidence do you have, that this event happened? At no time does eMember ever display or send passwords in clear text. Passwords are stored in the database, as a one way hash. Or perhaps this user did “soething stupid,” like using his email address as his “secret password,” and is upset that “his password” was sent to him in an email, LOL?

    I only mention that scenario, because in the last few weeks; we’ve had people asking about setting up eMember systems without passwords, and wanting to use email addresses as both the user name AND password.

    February 4, 2016 at 2:44 pm #72471
    fourstar
    Member

    The default email in eMember sent the member confirmation and password to the person. Here is one it sent to me which did the same thing: (I blanked out my user name and password in the example below.)

    Dear Kirk Foster

    Your registration is now complete!

    Registration details:

    Username: ************

    Password: *************

    Please login to the member area.

    Thank You

    February 4, 2016 at 2:54 pm #72472
    wzp
    Moderator

    That looks like the default email for the WordPress user registration side of your site.

    Are you only registering eMember users, or are you also registering WordPress users?

    February 4, 2016 at 3:05 pm #72473
    fourstar
    Member

    Only eMember users. All of the WordPress member options are disabled.

    February 4, 2016 at 3:08 pm #72474
    fourstar
    Member

    Here is the default email setting for registration complete in eMember:

    Dear {first_name} {last_name}

    Your registration is now complete!

    Registration details:

    Username: {user_name}

    Password: {password}

    Please login to the member area at the following URL:

    {login_link}

    Thank You

    February 4, 2016 at 4:02 pm #72475
    wzp
    Moderator

    You can remove the user name and password email tags from the template.

    February 4, 2016 at 4:03 pm #72476
    wzp
    Moderator

    Here is the complete list of email tags:

    https://support.tipsandtricks-hq.com/forums/topic/wp-emember-email-tags-reference-list-of-email-tags

    February 4, 2016 at 4:04 pm #72477
    fourstar
    Member

    Yes, we did that. Can you just explain the encryption in the database so I can reassure the member that his information is secure?

    February 4, 2016 at 4:12 pm #72478
    wzp
    Moderator

    The password is a one way hash; identical to the one used by WordPress. Once the password is encrypted and stored in the eMember database; it cannot be decrypted.

    The only reason the password is available as an email tag is because; the email is generated at the time the user picks their password. Once the registration process completes, there is no way to recover the unhashed password. The availability of the password as an email tag, is strictly as a courtesy “convenience” to the user, so that they can keep a copy in a “safe place.”

  • Author
    Posts
Viewing 10 posts - 1 through 10 (of 10 total)
  • You must be logged in to reply to this topic.
Log In

Forum Related

  • Forum Home
  • Forum Search
  • Forum Registration
  • Forum Login

Support Related Forms

  • Contact Us
  • Customer Support
  • Request a Plugin Update
  • Request Fresh Download Links

Useful Links

  • Plugin Upgrade Instructions
  • WP eStore Documentation
  • WP eMember Documentation
  • WP Affiliate Platform Documentation
  • Tips and Tricks HQ Home Page
  • Our Projects

Quick Setup Video Tutorials

  • WP eStore Video Tutorial
  • WP eMember Video Tutorial
  • WP Affiliate Platform Video Tutorial
  • Lightbox Ultimate Video Tutorial

Our Other Plugins

  • WP Express Checkout
  • Stripe Payments Plugin
  • Simple Shopping Cart Plugin
  • Simple Download Monitor

Copyright © 2025 | Tips and Tricks HQ