Secure Hash Keys
#1
Posted 08 February 2016 - 06:02 AM
either option a person could just copy and use to bypass someone's login very easily. Does anyone on here have an idea on how i can prevent this or any other way I could possibly implement a remember me button into computercraft.
#2
Posted 08 February 2016 - 06:43 AM
There will always be a trade-off between convenience and security when doing this kind of feature.
It's the same for a real website, an auth cookie is just sitting there in plaintext waiting to be read by somebody else or a virus.
Though, from your two options, I would choose to store a randomized authorization key since it would at least not leak the password.
Edited by Anavrins, 08 February 2016 - 06:44 AM.
#3
Posted 08 February 2016 - 06:54 AM
Anavrins, on 08 February 2016 - 06:43 AM, said:
There will always be a trade-off between convenience and security when doing this kind of feature.
It's the same for a real website, an auth cookie is just sitting there in plaintext waiting to be read by somebody else or a virus.
Though, from your two options, I would choose to store a randomized authorization key since it would at least not leak the password.
usually programs have the advantage of storing some unique identifier in the key. Though you can spoof those too its much easier to spoof the only real identifier we have os.computerID().
#4
Posted 08 February 2016 - 10:01 AM
#6
Posted 08 February 2016 - 01:22 PM
related idea, cookie is on CC-pocketPC and is encrypted and transmitted to client computer when needed
Edited by Lupus590, 08 February 2016 - 01:23 PM.
#7
Posted 08 February 2016 - 05:30 PM
However for safety of your users, watch this video to see how NOT to handle this. Here ya go.
Edited by Dragon53535, 08 February 2016 - 05:32 PM.
#8
Posted 08 February 2016 - 07:13 PM
#9
Posted 08 February 2016 - 09:04 PM
HDeffo, on 08 February 2016 - 07:13 PM, said:
Edited by Wojbie, 08 February 2016 - 09:05 PM.
#10
Posted 08 February 2016 - 09:24 PM
Wojbie, on 08 February 2016 - 09:04 PM, said:
HDeffo, on 08 February 2016 - 07:13 PM, said:
those are very difficult to port to computercraft though. And since true security is impossible in CC i think this is as secure as its gonna get
#11
Posted 08 February 2016 - 09:25 PM
2 user(s) are reading this topic
0 members, 2 guests, 0 anonymous users











