Jump to content

Security Questions


Djinnii

Recommended Posts

Hi All,

I'm wondering... a few of my users seem to have had their accounts hacked recently, so I wanted to know what I could do and how to help them avoid it happening in future.

My main question today is, is it possible for a minecraft (modded, emulated or otherwise) server to harvest a users minecraft name and password?

Link to comment
Share on other sites

No, it is not possible for a minecraft server to harvest usernames and passwords, because you don't authenticate with the server. You authenticate with Mojang's login servers, which then exchange session keys with the minecraft server. If they are getting their accounts stolen, its their fault, not yours.

Link to comment
Share on other sites

Wasn't so much wondering if it was my fault :P More, if they are connecting to other peoples servers who seem to me anyway a little... dubious... weather it was possible for them to steal the session keys and collect the password from that.. much in the same way you would steal a WEP key... (There is no need to transmit the actual password to a device past the initial handshake... but WEP does it anyway.)

Link to comment
Share on other sites

No, you cannot get the password from a session key. Session keys are randomly generated when you log in (to Mojang) and are unrelated to the password beyond the fact that you need your password to get one. It's possible they are all using some rogue client or other software that's stealing their passwords, or they all just have weak passwords.

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...