• Guest, we are doing a new map (refresh) for Herocraft. Gather your friends and get ready! Coming next Friday, 06/28/24 @ 7PM CT play.hc.to
    Read up on the guides and new systems! Here.
    View the LIVE Map here @ hc.to/map
    Stuck or have a problem? use "/pe create" to to open a ticket with staff (There are some known issues and other hotfixes we will be pushing asap)
  • Guest, Make sure to use our LAUNCHER! Read more here!

Suggestion xAuth and Spoutcraft

Status
Not open for further replies.

xexorian

Admin ZeeZo
Retired Staff
Joined
Apr 7, 2011
Location
USA
I recommend removing both the requirement of Spoutcraft and the xAuth plugin.

Both are broken forms of fine pottery at the moment and do not work, as their creators are currently striving to get them to work, as intended.

First of all, just naming the Authentication plugin has made it open to exploiting. Second of all, requiring email address and passwords is illegitimate and misleading. The plugin cannot actually email you and reset your password. It is not immune to data sniffing, and does not include any known form of solid encryption that can't be bypassed by your typical quad core computer within a few hours.

It is not safe to use emails and passwords, it is much safer to create temporary logins as I previously suggested using players KNOWN forum accounts and NEW passwords for INGAME only. or IGP. In-Game-Password. Instead of "IGN".

Furthermore, you do not need spoutcraft for this capability and a lot of people are having a hard time adjusting to the backwards logic of spoutcraft, and adding functionality where it was not needed because, (to simplify this logic in 2 words) "Less Clicks". Spoutcraft has made it a chore to do things that were previously easy to do. Such as seperating / commands into the ctrl function instead of alt+up arrow. Such as M turning off chat instead of opening your map. Such as the fact most users won't click on a map, they're viewing it, they'll drag and drop it and by sheer accident if they let go of it and click to fast they might discover you can add waypoints. The client last GUI. There's a ton more..

I could go on to throw a completely thorough bitchfit about how terrible my citizens and friends think spoutcraft is. But for now, I will savor the flavor of their suffering you are now causing.
 

donaldmax1

Soulsand
Joined
May 22, 2012
I notice a lot of people can't run spout or have a lot more lag on it personal I believe this ruins the Herocraft experience.
 

Kainzo

The Disposable Hero
Staff member
Founder
Adventure Team
Joined
Jan 7, 2011
Location
The 7th Circle of Heaven
We won't be removing it until the DNS issues are resolved.

All of this information is encrypted in a database, protected by 3 layers of networking security. The xauth plugin has a built in lock out time after X attempts - if someone is trying to spoof's someones session (Which is HIGHLY unlikely due to Spoutcraft being required) they will be locked out completely from the account.
 
Status
Not open for further replies.
Top