Forum

ASSIST, AMERICA'S ARMY COMMUNITY - RELIVE THE GLORY DAYS OF AMERICA'S ARMY 2.5

Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.


Messages - panqueques

Pages: [1]
1
News / Re: Welcome back to AAO25.com
« on: Friday, September 13, 2013, 13:36:57 PM »
I will grant you that. ;)

SSL is cheap though, might as well use it. The risks are pretty small though like you said, so perhaps it isn't worth your time which I completely understand.

2
News / Re: Welcome back to AAO25.com
« on: Friday, September 13, 2013, 13:27:46 PM »
It's not sent in clear text. There is a special hashing method inside Assist that hashes the passwords with salt before they're sent to Assist/Battletracker.
While on its face that may sound sufficient, unless the connection is encrypted with SSL, that hash itself is being sent in clear text. If someone can snoop and capture the network traffic, they can grab that hash and do a replay attack to login as you (without knowing your password), that is assuming that the salt doesn't change every time (rarely is that done in practice).

It is great however that the database containing usernames/passwords has salted hashed passwords stored rather than in plaintext.

You should really be using SSL for communication between Assist and the server for login data. (No need to buy a cert, just generate a self-signed one).

Pages: [1]

Download Assist

×

Download Game Client

Important: Battletracker no longer exists. However, old Battletracker accounts may still work. You can create a new 25Assist account here

Download Server Manager