|
|
The Inn A place to gather around and chat about almost any subject |
![]() |
|
Thread Tools
![]() |
Display Modes
![]() |
|
![]() |
#1 | |
Master
![]() ![]() ![]() Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
![]() ![]() |
![]() Quote:
I dont bother about https or http login, as they store passwords in a safe. I keep safe my own lan. Do they? I dont know. I bother about how they store my info. Do you? It's trivial to compare ONE password, but it seems they are comparing every chatline, to see if it contains the valid password. Do they crypt all the chunks between spaces before to compare it to a hash of the password? i doubt it. And that's not trivial. This is not about stupid persons, it's about stupid security implementations. who needs a warning about "you typed you password"?. I can only think in a bruteforce attacker. I know i typed my password. Im not stupid. If, as is implied in you message, this is a feature only for stupid people, well, maybe they get scared, or they just have a nice confirmation, or they just ignore any RED WARNING MESSAGE. But this system is not avoiding anything. And they can get this information privately, anyway.
__________________
I'm an outsider, outside of everything... RAM ![]() Elegida Miss Ignis 2009 por votación popular |
|
![]() |
![]() |
![]() |
#2 | ||||
Apprentice
![]() Join Date: Aug 2008
Location: UK
Posts: 93
![]() |
![]() Quote:
Quote:
Quote:
With regards to a brute force attack, even if the system is only checking your own password, I will agree that this might be possible, but only if the user is already logged in and is dumb enough to leave their terminal in a public place, without locking it. If that's the case then, quite frankly, they're asking for trouble. Its still more secure than web browsers offering to remember passwords. Quote:
I can't see it being any different to that to be perfectly honest.
__________________
Zodar - The Evil Bald Fu^wPerson... |
||||
![]() |
![]() |
![]() |
#3 | ||
Pledge
Join Date: Jan 2009
Posts: 22
![]() |
![]() Quote:
![]() I don't want NGD to encrypt everything, since i guess everything would slow down then - and hell, it is slow enough! Just do not give away your passwords - i think that is much more dangerous than unencrypted chats... Quote:
|
||
![]() |
![]() |
![]() |
#4 | |
Master
![]() ![]() ![]() Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
![]() ![]() |
![]() Quote:
Yes, my tests say that they are comparing every chat word you type, against your password. I dont really know how they do it. But it's one of two: 1. they compare plain text with plain text password. 2. they hash every word (every string between spaces) and then compare every result with your hashed password. And yes, i guess they asume that there are no spaces in the password, and that it's not finished but a dot (.) In any case, i dont like it. Regards!
__________________
I'm an outsider, outside of everything... RAM ![]() Elegida Miss Ignis 2009 por votación popular |
|
![]() |
![]() |
![]() |
#5 | |
Duke
![]() ![]() Join Date: Jan 2007
Posts: 3,939
![]() ![]() ![]() |
![]() Quote:
__________________
"Nunca un científico ha quemado a un religioso por afirmar a Dios sin pruebas". Manuel Toharia "uno empieza a darse cuenta que eso de no hacer ejercicio, comer y beber como si fuese la ultima cena y mantener la figura ya no existe...". Maryan Last edited by arlick; 03-27-2009 at 12:28 PM. |
|
![]() |
![]() |
![]() |
#6 | |
Master
![]() ![]() ![]() Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
![]() ![]() |
![]() Quote:
__________________
I'm an outsider, outside of everything... RAM ![]() Elegida Miss Ignis 2009 por votación popular |
|
![]() |
![]() |
![]() |
#7 | |
Duke
![]() ![]() Join Date: Jan 2007
Posts: 3,939
![]() ![]() ![]() |
![]() Quote:
![]()
__________________
"Nunca un científico ha quemado a un religioso por afirmar a Dios sin pruebas". Manuel Toharia "uno empieza a darse cuenta que eso de no hacer ejercicio, comer y beber como si fuese la ultima cena y mantener la figura ya no existe...". Maryan |
|
![]() |
![]() |
![]() |
#8 | |
Master
![]() ![]() ![]() Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
![]() ![]() |
![]() Quote:
![]() i will make my own tests (mythbusters style) [lang=es]wireshark al ataque![/lang]
__________________
I'm an outsider, outside of everything... RAM ![]() Elegida Miss Ignis 2009 por votación popular |
|
![]() |
![]() |
![]() |
#9 | |
Legend
![]() Join Date: Mar 2006
Location: Oslo
Posts: 2,176
![]() ![]() |
![]() Quote:
__________________
Surak ![]() |
|
![]() |
![]() |
![]() |
#10 | |
Master
![]() ![]() ![]() Join Date: Feb 2007
Location: Altaruk :) Posts:31,337
Posts: 446
![]() ![]() |
![]() Quote:
Password is stored in memory while the game is running. I didnt see any network trace of the password check. hint: scan your memory for text "Charactername:" (upper/lower case matters) Forget everything i said before (in this thread only) PD: Thanks Surak! Tell Kailer to answer my PM, or i will spam your inbox! ![]()
__________________
I'm an outsider, outside of everything... RAM ![]() Elegida Miss Ignis 2009 por votación popular |
|
![]() |
![]() |
![]() |
|
|