[removed]
[removed]
all it takes is a simple packet sniffer to see the only net connection they make is for resources.
It was primarily banned for the adware addition and CHARGING for features. And the users of said private plugin knew it did it, otherwise they couldn't of used it in first place.2nd: I find it quite hypocritical to allow plugins (I guess only "private" ones) which track you in some way then turn around and ban/criticize 3rd party apps that do the same thing you allow yourself (but actually states it publicly unlike some of your private ones)
And I'd like you to point out to me on every program that uses FFACE or the FFACE download page where it says it will report back something to identify your account? My plugin boldly says "you cant use this until you give me some information so I can add you to an access list" on the download page, wheres that kind of message on FFACE, or InsertEveryProgramThatUsesFFACE's page?
It's something everyone would love to have but RMT would exploit it deeply, so its limited to few people only who are worthy. Nothing malicious in the plugin that harms other players.3rd: Makes you wonder what kind of "private" plugins they have for windower. I'm going to go out on a limb and say a few defiantly do more then read memory for info.
You're free to stop using windower anytime you want. It's a service given to you free and never demanding donations.
[removed]
The security of the fface mechanism would be broken if all of the following were true:
1) The fface hash database were broken into, yielding a list of hashes for paid users
2) The fface hash mechanism were reverse-engineered to reveal how the salt and account identifier are obtained, and exactly how they are hashed
3) The account identifier is traced to something that meaningfully identifies players.
fface is technically relying on the security of #3, which is risky. If someone wrote a trojan plugin (under the guise of something useful!) that collected the salt, mystery account identifier, and something meaningful like active character name, they would soon breach #3. They could then use any of various means to breach #1 and take their own time to crack #2 to yield a partial list of players that paid for fface (partial because not everyone that paid for fface necessarily runs this trojan).
In security, a salt is trivial to know and does not affect bruteforcing time. All you have to do is examine the fface code. For all I know, the salt could be "fface" and that would do the job. Salt nullifies the use of rainbow tables that immediately break hashes, as these tables only work for a very finite input length. Given that md5 is already super-fast, having a salt is only a minor impediment.Also according to fface forums the md5 hashes are salted making it almost impossible to bruteforce unless you know the salt.
The fface database could be more secure if fface reported only multiple-round hashes, since those take longer to brute force and destroy rainbow tables.
md5 is very fast... a modern processor core can usually repeat it 5-10 million times a second, and specialized GPGPU code can use video cards to try hundreds of millions of keys a second. Of course, that means it's no inconvenience to hash your identifier millions of times and store the result in the database; bruteforcing that is now made millions of times harder - that's the sole purpose of multiplying the hash.
Playing devil's advocate, what's to stop program from only reporting identifiers during those resource/update checks? You still have to trust the developers.You are right, I didn't think of that. Should prove to everyone that has doubts about windower and it's plugins sending private data.
Here I was thinking it was something cool like a working Hermes. AH from anywhere in town is boring.![]()
How about the one that erases models for FPS increase/claiming!?
No way, get out.
Yep, I clearly know nothing about cryptography solely because the link that I grabbed with a minute of searching was not 100% proving the point. Not going to lie, I skimmed the article, but that said I wasn't writing my thesis, just making a post on an Internet forum. Stop being a tryhard.
The thread about B cups was better, but if you read page 1&2 and then skip most of the way to page 4 this one isn't bad either.
Enough about MD5, somebody set up the Sath Signal and let the Intarweb Lawyering of MD5 cryptography commence!
The point remains that you knew so little about cryptography and hashing to have interpreted a semi-technical article and then criticized fface for implementing md5.
The md5 collision weakness has been public for many years and is the only documented cryptographic weakness for md5. It comes into play when a malicious author offers an innocent-looking program or document to be signed with md5 and then releases an altered program or document hashing to the same value and thus masquerading as safe. Since SE is the author of your account-identifying codes (the input of the fface hash), the published md5 weakness has no bearing on the uniqueness of the hash output.
That fface uses md5 hashing does not affect the reversibility/security of the server hash database. Anyone who started chuckling soon as they heard 'md5' doesn't know cryptography. fface would be subject to the same concerns were it to employ SHA-2 or government-grade AES-192/256. The security is in the implementation, not the algorithm itself.
Originally Posted by FFEVO
Originally Posted by Rzn
Not only does he want to get sued by Square-Enix by running his donation/subscription scheme. But now he wants to threaten people?Originally Posted by Rzn
Spoiler: show
edit: Also not siding with Aikar in anyway. I just don't see the point of the ethugging, especially when I'm not seeing proof anywhere.
Juicy.
Other developers/users that are interested in current issues within the community link from their blogs all the time. Implying I camped the site for this information is pretty sharp.
Where?
Something that not only interests me, but a huge part of the XI community cannot be discussed? Gotcha, I don't see any "gossip" besides what he actually posted.
Sounds like we have a fight on our hands
http://i344.photobucket.com/albums/p...geek_fight.jpg