Since when do the devs do resurections on request?

Thoughts on the further development of Haven & Hearth? Feel free to opine!

Re: Since when do the devs do resurections on request?

Postby ElGato » Wed Sep 15, 2010 7:01 am

loftar wrote:The client itself never looks at the cleartext password at all beyond hashing it with SHA-256, and thus the server never sees cleartext passwords at all (except over HTTP, since that cannot be fixed other than by patching the web browsers themselves).

I wonder how, then, the goon client sends the password of the user to a web server.
burgingham wrote:We are all Gato, and Gato is Delamore of course. Goons blablabla...

Caradon wrote:Gato, the anti-ghandi

Sabinati wrote:yeah we're gonna kill you gato!!!
User avatar
ElGato
 
Posts: 1945
Joined: Tue Nov 10, 2009 2:10 am

Re: Since when do the devs do resurections on request?

Postby loftar » Wed Sep 15, 2010 7:21 am

Well; the client does, of course, know the password (since you typed it into it). The default client simply doesn't care more about it than that. The important part being that there's no part of security that requires the client to deal more with it than that.
"Object-oriented design is the roman numerals of computing." -- Rob Pike
User avatar
loftar
 
Posts: 9058
Joined: Fri Apr 03, 2009 7:05 am

Re: Since when do the devs do resurections on request?

Postby Granger » Wed Sep 15, 2010 11:52 am

ElGato wrote:I wonder how, then, the goon client sends the password of the user to a web server.
Still noone has shown me the code in the client doing this.

Picture or it didn't happen.

Apart from that, the only things i really miss in the original client are:
- resizing of client window, the nice way how Gilbertus managed it
- option to disable music completely once and for all, from Pachos
- multiple toolbars (since 10 hotkeys are not enough) from Pachos
- nightvision and a modification to server enforcing the use of lightsources to be able to interact with objects while in pitch black (to level they playing field and even resource consumption between people who like ambiente, and the ones who don't want to destroy their RL vision when playing at ingame night)
- functioning ingame mapping system with export function (so bigger high-resolution maps can be stitched together by 3rd party tools)

In case this would get backported i (think not alone with this) would see no use in a modified client, thus ending the 'client x steals password for <faction>' debate.
⁎ Mon Mar 22, 2010 ✝ Thu Jan 23, 2020
User avatar
Granger
 
Posts: 9254
Joined: Mon Mar 22, 2010 2:00 pm

Re: Since when do the devs do resurections on request?

Postby ElGato » Wed Sep 15, 2010 1:23 pm

Granger wrote:
ElGato wrote:I wonder how, then, the goon client sends the password of the user to a web server.
Still noone has shown me the code in the client doing this.

Picture or it didn't happen.

Apart from that, the only things i really miss in the original client are:
- resizing of client window, the nice way how Gilbertus managed it
- option to disable music completely once and for all, from Pachos
- multiple toolbars (since 10 hotkeys are not enough) from Pachos
- nightvision and a modification to server enforcing the use of lightsources to be able to interact with objects while in pitch black (to level they playing field and even resource consumption between people who like ambiente, and the ones who don't want to destroy their RL vision when playing at ingame night)
- functioning ingame mapping system with export function (so bigger high-resolution maps can be stitched together by 3rd party tools)

In case this would get backported i (think not alone with this) would see no use in a modified client, thus ending the 'client x steals password for <faction>' debate.


Anyone that wishes to see the code, PM me.
I won't post it publicly.
burgingham wrote:We are all Gato, and Gato is Delamore of course. Goons blablabla...

Caradon wrote:Gato, the anti-ghandi

Sabinati wrote:yeah we're gonna kill you gato!!!
User avatar
ElGato
 
Posts: 1945
Joined: Tue Nov 10, 2009 2:10 am

Re: Since when do the devs do resurections on request?

Postby Spiff » Wed Sep 15, 2010 3:04 pm

Granger wrote:
ElGato wrote:I wonder how, then, the goon client sends the password of the user to a web server.
Still noone has shown me the code in the client doing this.

Picture or it didn't happen.


Nah, it does. No shame in admitting it here. It's nothing underhanded, it's clearly posted at the top of the goon client download page:

Internet Safety Tip: Don't use the same password for Haven & Hearth as anywhere else. You are identified with your username and password to the Havengoons site to ensure that this tool remains goons-only.


It's not a difficult change. There are other clients out there doing the same that aren't so open with the fact. Just so folks know, unless you've been spying on goons and stealing our client a la Gato, your password is (mostly) safe :v
User avatar
Spiff
 
Posts: 356
Joined: Sun Jul 12, 2009 9:33 pm

Re: Since when do the devs do resurections on request?

Postby ElGato » Wed Sep 15, 2010 3:23 pm

Spiff wrote:
Granger wrote:
ElGato wrote:I wonder how, then, the goon client sends the password of the user to a web server.
Still noone has shown me the code in the client doing this.

Picture or it didn't happen.


Nah, it does. No shame in admitting it here. It's nothing underhanded, it's clearly posted at the top of the goon client download page:

Internet Safety Tip: Don't use the same password for Haven & Hearth as anywhere else. You are identified with your username and password to the Havengoons site to ensure that this tool remains goons-only.


It's not a difficult change. There are other clients out there doing the same that aren't so open with the fact. Just so folks know, unless you've been spying on goons and stealing our client a la Gato, your password is (mostly) safe :v

eh I wasn't spying on anyone. just looked through old irc logs and found where rage linked me to it.
and, I knew about the password thing so, I haven't logged in on it with any of my main accounts :/
burgingham wrote:We are all Gato, and Gato is Delamore of course. Goons blablabla...

Caradon wrote:Gato, the anti-ghandi

Sabinati wrote:yeah we're gonna kill you gato!!!
User avatar
ElGato
 
Posts: 1945
Joined: Tue Nov 10, 2009 2:10 am

Re: Since when do the devs do resurections on request?

Postby DatOneGuy » Wed Sep 15, 2010 3:39 pm

The only issue I see here is that if the source is compromised (as it was) anyone can find out the website, so I suppose now everyone who uses it has to put their faith in that the website is 100% secure, and no website is 100% secure.


All their choice though, hopefully no one is stupid enough to have used a password for anything else.
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
. . . . . . . . . . . . . . . . .Hi. . . . . . . . . . . . . . . . . . . . . . . .
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
User avatar
DatOneGuy
 
Posts: 5553
Joined: Sun Apr 18, 2010 7:50 am
Location: I'm in Miami, trick.

Re: Since when do the devs do resurections on request?

Postby Spiff » Wed Sep 15, 2010 3:47 pm

DatOneGuy wrote:All their choice though, hopefully no one is stupid enough to have used a password for anything else.


It's a convenient way for me to raise funds for my new yacht B-)
User avatar
Spiff
 
Posts: 356
Joined: Sun Jul 12, 2009 9:33 pm

Re: Since when do the devs do resurections on request?

Postby Avu » Wed Sep 15, 2010 9:30 pm

Why would anyone use your goon only client unless it had something no other client had like say macros?
"Since all men count themselves righteous, and since
no righteous man raises his hand against the innocent,
a man need only strike another to make him evil."
User avatar
Avu
 
Posts: 3000
Joined: Sat Oct 31, 2009 1:00 pm

Re: Since when do the devs do resurections on request?

Postby Spiff » Wed Sep 15, 2010 9:40 pm

Avu wrote:Why would anyone use your goon only client unless it had something no other client had like say macros?


Image

Or maybe because we've had things like multiple hotbars with resizable windows with improved vision toggles for weeks ahead of public clients. hmmmmm. i'll let you decide.
User avatar
Spiff
 
Posts: 356
Joined: Sun Jul 12, 2009 9:33 pm

PreviousNext

Return to Critique & Ideas

Who is online

Users browsing this forum: Claude [Bot] and 1 guest