TMForever storing passwords in clear text

Any problem ? Don't panic! We have the solution !

Moderator: TM-Patrol

Post Reply
knox
highway camper
highway camper
Posts: 2
Joined: 12 Sep 2018 18:24
Owned TM-games: knox

TMForever storing passwords in clear text

Post by knox » 12 Sep 2018 18:30

Hey there,

I just got to know that you are storing the users' passwords in clear text in your database.
Why so? Please consider hashing our passwords! These are fundamental private information. I do not doubt your security or your honesty, but no system is safe. And I do not want any hackers or one of your employees to look at my password - it should not even be possible! I am an IT specialist and password hashing is state of the art... storing clear text passwords is outdated for years...

kind regards

Xymph
Pit Crew
Pit Crew
Posts: 5685
Joined: 19 Aug 2007 12:58
Owned TM-games: TMN, TMU, TMF, TM²
Contact:

Re: TMForever storing passwords in clear text

Post by Xymph » 13 Sep 2018 16:08

An long-standing problem in an old game which hasn't received updates for years, so this won't be fixed.
Developer of XASECO for TMF/TMN ESWC & XASECO2 for TM²: see XAseco.org
Find your way around the Mania community from the TMN ESWC hub, TMF hub, TM² hub, and SM hub

knox
highway camper
highway camper
Posts: 2
Joined: 12 Sep 2018 18:24
Owned TM-games: knox

Re: TMForever storing passwords in clear text

Post by knox » 13 Sep 2018 16:49

to be honest I cannot understand that... this is a small amount of lines of code which have to be changed... 3 days maximum...
You want to tell me you are too lazy for this small effort? And by the way you are the only one to blame for this workload... better think before you code the next time...

But if you can live with the problem of high risk for the users and do not want to make some code changes... at least make an anouncement ingame about this problem - if you are the one to decide that the users passwords are not worth the effort of protecting them, give them the chance to decide whether they are okay with it!

Xymph
Pit Crew
Pit Crew
Posts: 5685
Joined: 19 Aug 2007 12:58
Owned TM-games: TMN, TMU, TMF, TM²
Contact:

Re: TMForever storing passwords in clear text

Post by Xymph » 13 Sep 2018 18:57

knox wrote:
13 Sep 2018 16:49
to be honest I cannot understand that... this is a small amount of lines of code which have to be changed... 3 days maximum...
You want to tell me you are too lazy for this small effort? And by the way you are the only one to blame for this workload... better think before you code the next time...

But if you can live with the problem of high risk for the users and do not want to make some code changes... at least make an anouncement ingame about this problem - if you are the one to decide that the users passwords are not worth the effort of protecting them, give them the chance to decide whether they are okay with it!
If your use of "you" refers to Nadeo, you may have a point but are apparently unfamiliar with how they changed focus to their newer ManiaPlanet platform, and abandoned (almost all) work on the old games. Only master server issues are still monitored for and resolved.

If your use of "you" refers to me, you're mistaken, as I didn't code any part of the client or server or user administration, and don't work for Nadeo. ;)
Developer of XASECO for TMF/TMN ESWC & XASECO2 for TM²: see XAseco.org
Find your way around the Mania community from the TMN ESWC hub, TMF hub, TM² hub, and SM hub

Post Reply