Warning For Custom Clients

Forum for alternative clients, mods & discussions on the same.

Warning For Custom Clients

Postby shubla » Fri Oct 09, 2015 9:54 am

Dont log on with public client via public computer. In most cilents it wol store your password to .haven file in "username:password" format. This might go in wrong hands
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Warning For Custom Clients

Postby EnderWiggin » Fri Oct 09, 2015 10:26 am

what .haven file? where is it located? What clients write it?
User avatar
EnderWiggin
 
Posts: 1070
Joined: Sat Mar 20, 2010 8:23 pm

Re: Warning For Custom Clients

Postby shubla » Fri Oct 09, 2015 1:09 pm

Atleast on amber.
C:\Users\user\.haven
Theres "loginInfo.conf" with passwords and stuff.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Warning For Custom Clients

Postby EnderWiggin » Fri Oct 09, 2015 1:12 pm

shubla wrote:Atleast on amber.
C:\Users\user\.haven
Theres "loginInfo.conf" with passwords and stuff.
Ah, so that's amber's issue. I don't store passwords - only cookies that are easy to reset. They are stored in accounts.json in client folder.
User avatar
EnderWiggin
 
Posts: 1070
Joined: Sat Mar 20, 2010 8:23 pm

Re: Warning For Custom Clients

Postby shubla » Fri Oct 09, 2015 1:47 pm

EnderWiggin wrote:
shubla wrote:Atleast on amber.
C:\Users\user\.haven
Theres "loginInfo.conf" with passwords and stuff.
Ah, so that's amber's issue. I don't store passwords - only cookies that are easy to reset. They are stored in accounts.json in client folder.

Its good that way, they dont go into random computers if youre using usb stick. but in other way people might share them accidentally with others. I suggest romovs to change it.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Re: Warning For Custom Clients

Postby romovs » Fri Oct 09, 2015 2:48 pm

shubla wrote:Atleast on amber.
C:\Users\user\.haven
Theres "loginInfo.conf" with passwords and stuff.


It doesn't write any settings to files at all. logininfo.conf is from somewhere else.
User avatar
romovs
 
Posts: 1473
Joined: Sun Sep 29, 2013 9:26 am
Location: The Tabouret

Re: Warning For Custom Clients

Postby bdew » Fri Oct 09, 2015 4:55 pm

shubla wrote:Dont log on with public client via public computer. In most cilents it wol store your password to .haven file in "username:password" format. This might go in wrong hands


FYI - my client will have a similar "save login" option in the next release.

It is opt-in - you need to mark a checkbox that's clearly marked as unsafe and colored in red.

It will also have an accompanying text in the readme:

readme wrote:Warning - Account Management
If you check "save login" on login screen - the client will save your password, in clear text, either in your registry (Windows) or user folder (Mac/Linux).
This is inherently unsafe. It was added as a trade off between convenience and security after requests from multiple users and friends.
I do not recommend using this option.
User avatar
bdew
 
Posts: 179
Joined: Mon Mar 22, 2010 3:27 pm

Re: Warning For Custom Clients

Postby borka » Tue Oct 20, 2015 12:37 pm

romovs wrote:It doesn't write any settings to files at all. logininfo.conf is from somewhere else.


confirmed
User avatar
borka
 
Posts: 9965
Joined: Thu Feb 03, 2011 7:47 pm
Location: World of Sprucecap

Re: Warning For Custom Clients

Postby jaguar » Thu Oct 29, 2015 5:28 pm

romovs wrote:
shubla wrote:Atleast on amber.
C:\Users\user\.haven
Theres "loginInfo.conf" with passwords and stuff.


It doesn't write any settings to files at all. logininfo.conf is from somewhere else.


But it write password to registry. And you can access those passwords using regedit if it is public user logged in...so, not secure. Please consider to use tokens.
User avatar
jaguar
 
Posts: 251
Joined: Sun Jan 16, 2011 11:59 pm

Re: Warning For Custom Clients

Postby shubla » Thu Oct 29, 2015 8:07 pm

jaguar wrote:
romovs wrote:
shubla wrote:Atleast on amber.
C:\Users\user\.haven
Theres "loginInfo.conf" with passwords and stuff.


It doesn't write any settings to files at all. logininfo.conf is from somewhere else.


But it write password to registry. And you can access those passwords using regedit if it is public user logged in...so, not secure. Please consider to use tokens.

Theyre very easy to dig up i agree. But i think some more secure way doing that would be very difficult maybe even cost some money.
Image
I'm not sure that I have a strong argument against sketch colors - Jorb, November 2019
http://i.imgur.com/CRrirds.png?1
Join the moderated unofficial discord for the game! https://discord.gg/2TAbGj2
Purus Pasta, The Best Client
User avatar
shubla
 
Posts: 13043
Joined: Sun Nov 03, 2013 11:26 am
Location: Finland

Next

Return to The Wizards' Tower

Who is online

Users browsing this forum: Nerun and 7 guests