Forum

ASSIST, AMERICA'S ARMY COMMUNITY - RELIVE THE GLORY DAYS OF AMERICA'S ARMY 2.5

Author Topic: Assist is back online!  (Read 21387 times)

0 Members and 1 Guest are viewing this topic.

Offline shadi1230

Re: Assist is back online!
« Reply #45 on: Saturday, September 14, 2013, 05:27:28 AM »
guys i have an runtime error

Offline shadi1230

Re: Assist is back online!
« Reply #46 on: Saturday, September 14, 2013, 05:36:01 AM »
For me (http://sourceforge.net/projects/aa25assist/files/Binaries/25Assist.zip/download) download does not start right away. Why?

Or does the game start receiving this error:



i have a problem why how to fix it

Offline Mixk

Re: Assist is back online!
« Reply #47 on: Saturday, September 14, 2013, 05:47:07 AM »
Thanks guys for getting things up and running.   :beer:
I won't be wronged. I won't be insulted. I won't be laid a-hand on. I don't do these things to other people, and I require the same from them.

Offline [K][K].pcqdbt

  • Jr. Member
  • **
  • Posts: 24
    • View Profile
Re: Assist is back online!
« Reply #48 on: Saturday, September 14, 2013, 05:47:55 AM »
The screenshots are being taken when Assist requests them. Most users will never have screenshots taken of their computer. The screenshots are only a step for those players that are suspicious. When those screenshots are taken, they are only accessible by us devs.

ATM the most important is to have assist running, so it's OK for a temporary solution. But please, let's have a talk about security... Why are you sure that only assist devs can initiate/view screenshots? Think about MITM attacks, wifi sniffing, etc. If assist has that much power over your computer, an adversary may have a very cheap way to compromise a system (not game related). My recommendation:
  • design the security, without ad-hoc modifications (analyze threat models, etc)
  • make it public (preferably open source) - gaining trust is easier that way

(I trust you and the other contributors and I'm sure that all features are made with good intentions, but ad-hoc solutions are prone to serious errors.)

Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: Assist is back online!
« Reply #49 on: Saturday, September 14, 2013, 05:53:56 AM »
ATM the most important is to have assist running, so it's OK for a temporary solution. But please, let's have a talk about security... Why are you sure that only assist devs can initiate/view screenshots? Think about MITM attacks, wifi sniffing, etc. If assist has that much power over your computer, an adversary may have a very cheap way to compromise a system (not game related). My recommendation:
  • design the security, without ad-hoc modifications (analyze threat models, etc)
  • make it public (preferably open source) - gaining trust is easier that way

(I trust you and the other contributors and I'm sure that all features are made with good intentions, but ad-hoc solutions are prone to serious errors.)
I think we can't stop MITM attacks and wifi sniffing, Assist is vulnerable just as your web browser or instant messanger is.

We can make the communication flow through a more secure channel BUT nothing is perfect,
See the recent News  ;)
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: Assist is back online!
« Reply #50 on: Saturday, September 14, 2013, 06:02:56 AM »
Anyone else having problems with brightness settings..? I cannot change them at all, the sliders move but nothing happens and changing them from assist makes no difference either.
if you are using Windows 8, we will fix it in the next hours :P (probably missing file on our end sry)
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline Rob_LD

Re: Assist is back online!
« Reply #51 on: Saturday, September 14, 2013, 06:08:29 AM »
This screenshot "feature" is a no go.


@Spanky
Quote
Like use Assist to harvest passwords and try social engineering to gain access to your digital accounts. A lot of people use the same password for everything. The screenshots are not for public viewing and frankly, they're not being taken at a timed interval.
If it become public that there is a private data stored at the AAO-project you can bet your ass this will allure the bad guys sooner or later.

What is better than breaking into hundreds of PC's?
Right: Breaking into one insecure system which keeps their privacy's.

Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: Assist is back online!
« Reply #52 on: Saturday, September 14, 2013, 06:17:28 AM »
This screenshot "feature" is a no go.


@SpankyIf it become public that there is a private data stored at the AAO-project you can bet your ass this will allure the bad guys sooner or later.

What is better than breaking into hundreds of PC's?
Right: Breaking into one insecure system which keeps their privacy's.
hmm, no one tried but, Screenshots aren't stored or sent to our server
 the only private data are the Passwords that are encrypted and salted, most usernames are publicy, but why do we store those PWs? cuz with them we can set  up a System in case BT has any failure etc, we do Store points to Next Honor and Player Honor too, basic info to setup a login system IF needed.
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline [K][K].pcqdbt

  • Jr. Member
  • **
  • Posts: 24
    • View Profile
Re: Assist is back online!
« Reply #53 on: Saturday, September 14, 2013, 06:19:23 AM »
I think we can't stop MITM attacks and wifi sniffing, Assist is vulnerable just as your web browser or instant messanger is.

We can make the communication flow through a more secure channel BUT nothing is perfect,
See the recent News  ;)

Math is almost perfect :) General consensus is that even NSA can't break it, but they are doing their nasty things mostly with cheating.

Yes, using secure channels would be a must, with proper pubkey authentication (to mitigate easy MITM threats). Security is all about making an attack more expensive than the possible gain.

There are two aspects here: 1) protecting the game environment (aa+assist) from hackers and 2) protecting the host system from compromises through assist. As I see, only 1) is being addressed, and the measures for doing that can hurt 2) in terrible ways.

(Please also see my post from yesterday.)

Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: Assist is back online!
« Reply #54 on: Saturday, September 14, 2013, 06:25:18 AM »
Math is almost perfect :) General consensus is that even NSA can't break it, but they are doing their nasty things mostly with cheating.

Yes, using secure channels would be a must, with proper pubkey authentication (to mitigate easy MITM threats). Security is all about making an attack more expensive than the possible gain.

There are two aspects here: 1) protecting the game environment (aa+assist) from hackers and 2) protecting the host system from compromises through assist. As I see, only 1) is being addressed, and the measures for doing that can hurt 2) in terrible ways.

(Please also see my post from yesterday.)
we have Unreleased work wich has improved somethings, you guys won't see changes to the Auth system cuz theres no need for us to mention, but sure there were a few changes regarding security in all that time.
this project was also developed by common ppl, without great coding Skill, but we are getting better :)
Spanky will read ur post, i'm not into that area :D
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline [K][K].pcqdbt

  • Jr. Member
  • **
  • Posts: 24
    • View Profile
Re: Assist is back online!
« Reply #55 on: Saturday, September 14, 2013, 06:33:41 AM »
Spanky will read ur post, i'm not into that area :D
It's not just for Spanky, it's for all devs, I was just seeing him as some kind of coordinator :) So if you or other devs think that someone with strong CS background would be good to talk to, please send me a PM on the topic.

Offline Rob_LD

Re: Assist is back online!
« Reply #56 on: Saturday, September 14, 2013, 06:36:51 AM »
Quote
hmm, no one tried but, Screenshots aren't stored or sent to our server
They don't even need to be stored.
If someone break into the server he can pickup the data in real time.


Quote
this project was also developed by common ppl, without great coding Skill
What makes the whole thing even worse.


BTW:
I don't even bother about 2-3 cheaters, what I am really concerned about is my privacy.


Someone else stated it before:
No game is it worth to run such a risk.

Offline Possessed

  • bWpnRecoil == False;
  • Administrator
  • Epic Poster
  • *
  • Posts: 3,620
  • You suffer, but why?!
    • View Profile
  • AA: Possessed
Re: Assist is back online!
« Reply #57 on: Saturday, September 14, 2013, 06:56:58 AM »
It's not just for Spanky, it's for all devs, I was just seeing him as some kind of coordinator :) So if you or other devs think that someone with strong CS background would be good to talk to, please send me a PM on the topic.
sure, I just dont enter into contacting ppl etc :D

Rob, online almost everything is vulnerable, if want to be really safe go hide below ur bed,
if you have anything that can improve assist as you wish, you can show and discuss with us;
see pcqdt, he knows that assist lack is X aspects and is willing to help, not bashing the work done for free in someone elses spare time. you can say, but if you can help to improve it, why not?
These things I have spoken unto you, that in me ye might have peace. In the world ye shall have tribulation: but be of good cheer; I have overcome the world.
John 16:33


Offline [SWISS]Merlin

Re: Assist is back online!
« Reply #58 on: Saturday, September 14, 2013, 07:10:26 AM »
thank you guys for doing this great job !!!

Offline Rob_LD

Re: Assist is back online!
« Reply #59 on: Saturday, September 14, 2013, 07:16:39 AM »
Quote
Rob, online almost everything is vulnerable, if want to be really safe go hide below ur bed,
Yes, you have to make compromises.
It's always a balance of benefit-risk.

But when it comes to a video game there is almost no benefit which would justify this lack of privacy.


There is a good reason why Punkbuster don't make screenshots while the game is minimized.

 

Download Assist

×

Download Game Client

Important: Battletracker no longer exists. However, old Battletracker accounts may still work. You can create a new 25Assist account here

Download Server Manager