• Visit Rebornbuddy
  • Visit Panda Profiles
  • Visit LLamamMagic
  • why we can't use a password?

    Discussion in 'Honorbuddy Forum' started by brainAbuddy, Apr 30, 2014.

    1. brainAbuddy

      brainAbuddy Active Member

      Joined:
      Aug 12, 2010
      Messages:
      2,180
      Likes Received:
      11
      Trophy Points:
      38
      hey duddies!

      just a question.
      why do we can't use a password for launching HB?
      because it's not hard to steal your code. you just need to get into the HB file and steal the GlobalSettings.xml and there you could see the code in raw text.
      I remember that you could use a password back in the days, but why is it removed?
      and just looking into the "GlobalSettings.xml" file I see that there is a code saying <Password></Password> it would be weird when the password is safe there.
       
    2. chinajade

      chinajade Well-Known Member Moderator Buddy Core Dev

      Joined:
      Jul 20, 2010
      Messages:
      17,540
      Likes Received:
      172
      Trophy Points:
      63
      Hi, Madcow344,

      Nice find. I was under the impression that the key was hashed. I don't know if something changed, or its always been that way.

      In either case, we've opened HB-753 ("User's "Key" should be hashed/encrypted in GlobalSettings.xml") against the issue. We'll have to see what the senior staff has to say about the issue.

      cheers,
      chinajade
       
    3. nooblet

      nooblet Active Member

      Joined:
      May 4, 2012
      Messages:
      1,419
      Likes Received:
      12
      Trophy Points:
      38
      They gotta get into your computer first so why worry.
       
    4. chinajade

      chinajade Well-Known Member Moderator Buddy Core Dev

      Joined:
      Jul 20, 2010
      Messages:
      17,540
      Likes Received:
      172
      Trophy Points:
      63
      Just a follow up...
      HB-753 ("User's "Key" should be hashed/encrypted in GlobalSettings.xml") has been marked as resolved, so it should be available in the next Honorbuddy (post-.732) release.

      cheers,
      chinajade
       
    5. Jericho316

      Jericho316 New Member

      Joined:
      Aug 29, 2011
      Messages:
      14
      Likes Received:
      0
      Trophy Points:
      1
      Because getting hold of that information would be very simple for someone with malicious intent - and getting into the computer first would be simple to do.

      (Purposely not saying how because while the fix for this issue is not yet released, the "attack" is still possible)
       
    6. brainAbuddy

      brainAbuddy Active Member

      Joined:
      Aug 12, 2010
      Messages:
      2,180
      Likes Received:
      11
      Trophy Points:
      38
      I get many poeple asking me for there help.
      I just need to tell something to give me there settings volder and taaadaaa!

      it's not that hard to do!

      but I'm glad there will be an password support in the next version


      EDIT::
      I hope there would be a good enough security when I replace me own settings to me "victims" setting that this would not work
       
      Last edited: May 2, 2014
    7. Giwin

      Giwin Well-Known Member Buddy Store Developer

      Joined:
      Dec 3, 2011
      Messages:
      3,431
      Likes Received:
      49
      Trophy Points:
      48
      inb4 lots of support threads asking about key
       

    Share This Page