Urban Terror Forums: AUTH logged me in as a random player - Urban Terror Forums

Jump to content

 Login | Register 
Advertisement
  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

AUTH logged me in as a random player Rate Topic: -----

No, I haven't touched my authkey

#21 User is offline   xesya Icon

  • Account: xesya
  • Main tag: #rekt.
  • Country:
  • Joined: 23-November 11
  • Posts: 40

Posted 10 November 2013 - 09:41 PM

Posted Image

http://www.urbanterr.../profile/xesya/
http://www.urbanterr...file/goosfraba/

if he hax its not my fault
R.I.P. Brainie *30-December '10 - †25-January '14


#23 User is offline   Nikki Icon

  • Account: nikki
  • Main tag: diRf!
  • Country:
  • Joined: 17-April 12
  • Posts: 427

Posted 10 November 2013 - 11:28 PM

Was auth down last night too?

Posted Image


#24 User is offline   Driller Icon

  •   community admin   
  • Account: driller
  • Main tag: uJ|
  • Country:
  • Joined: 28-February 10
  • Posts: 1,001

Posted 11 November 2013 - 12:14 AM

I still dont understand it why its not a problem that the authnames are not the real authnames, guess im stupid but i gonna post the stupid problem -)

Example.
I play and i see my auth changes to NuB.
I know there is a regular player on that server with name/auth NuB

Now i change my name to NuB and i start cheating the obvious way.
There is no admin online, so the other regulars will demo me and post it on the server/clan forum. With a screenshot of who is cheating.
The admin will see the demo and draw their conclusions based on the demo, since they believe authnames are the real names.
When the real NuB comes on the server, he will be immediately banned by a admin. Or he is already banned by his logged ip before he can enter server.

Above way to ban players is pretty common.
But somehow FS tells me that there is no reason to worry?

Untill now most servers dont care to much about the auth-bans, most servers i play on have auth enabled but not forced.... But they do care about their own banning methods, and the extra feature (auth) is not helping them since auth is not working properly....

#25 User is offline   beautifulNihilist Icon

  •   verified user   

Posted 11 November 2013 - 01:26 AM

View PostDriller, on 11 November 2013 - 12:14 AM, said:

I still dont understand it why its not a problem that the authnames are not the real authnames, guess im stupid but i gonna post the stupid problem -)

Example.
I play and i see my auth changes to NuB.
I know there is a regular player on that server with name/auth NuB

Now i change my name to NuB and i start cheating the obvious way.
There is no admin online, so the other regulars will demo me and post it on the server/clan forum. With a screenshot of who is cheating.
The admin will see the demo and draw their conclusions based on the demo, since they believe authnames are the real names.
When the real NuB comes on the server, he will be immediately banned by a admin. Or he is already banned by his logged ip before he can enter server.

Above way to ban players is pretty common.
But somehow FS tells me that there is no reason to worry?

Untill now most servers dont care to much about the auth-bans, most servers i play on have auth enabled but not forced.... But they do care about their own banning methods, and the extra feature (auth) is not helping them since auth is not working properly....


Yes, every word of this.

I would like a more public announcement of this and if possible a greater explanation.
With people trading Auths there is a pretty significant communication breakdown somewhere that is a serious risk. If someone figures out how to break Auth on purpose, and even worse to specific targets, then Auth is a threat and not tool.

Please do not sweep this under the rug: if you do not make server admins aware of this situation, I do not feel safe about my Auth.
Nitro can only cuddle me for so long

[edit: disable AUTH server until fixed?]

<3

This post has been edited by beautifulNihilist: 11 November 2013 - 05:42 AM


bullet_loaderAdvertisement

#26 User is offline   Seven of Nine Icon

  •   former FS member   
  • Account: sevenofnine
  • Main tag: |it|
  • Country:
  • Joined: 30-April 09
  • Posts: 1,638

Posted 11 November 2013 - 08:45 AM

Fenix already answered your question 1 page back:

View PostFenix, on 04 November 2013 - 02:38 AM, said:

We can't answer such questions not because we are not capable of, but because our AUTH protocol MUST stay closed in order to work properly (and so the AC). I can tell you that what Nitro stated is 100% true.

In other words you'll have to trust what the expert says is right :)

#27 User is offline   Nikki Icon

  • Account: nikki
  • Main tag: diRf!
  • Country:
  • Joined: 17-April 12
  • Posts: 427

Posted 11 November 2013 - 08:57 AM

That doesn't answer how that's going to fix admins on servers banning the wrong people or assuming who people are, etc.

This post has been edited by Nikki: 11 November 2013 - 08:57 AM


#28 User is offline   beautifulNihilist Icon

  •   verified user   

Posted 11 November 2013 - 07:59 PM

Yes, at this point we are not looking for answers.
This is a request for action.

Regardless of if the AC is mixed up with the Auth or not, THE GAME IS, and there is a player's-security issue that requires attention.

I will not be using Auth until it is addressed.
This is not meant as some kind of ultimatum, but you will not have my participation in Auth until it is fixed.

This post has been edited by beautifulNihilist: 11 November 2013 - 08:07 PM


#29 User is offline   sneakers Icon

  • Account: sneakers
  • Joined: 11-March 10
  • Posts: 211

Posted 12 November 2013 - 07:01 PM

I've been falsely accused of cheating before (by mustang of all people) and have no desire to repeat that experience. Is it possible that someone else could cheat while bugged out with my auth account? There is fear in the air :ph34r:

#30 User is offline   beautifulNihilist Icon

  •   verified user   

Posted 13 November 2013 - 12:39 AM

At this point, I haven't heard of anyone using Someone Else's Auth on purpose.
But the way Auth has been touted as such an absolute identifying feature leads people to put a great deal of trust in it.
With all of the (understandable) pussyfooting around the details, we are not given a clear sign of just how much trust to put in the Auth system.
With Auth names getting mixed up, it is clear that we need to NOT put infallible trust in the logins and treat players similarly to 4.1, by paying attention to IP addresses; at least until whatever is broken is fixed.
My main concern is admin who don't know the situation and will take Auth names for clean and usable fingerprints.


I don't distrust that what the expert says is right; I'll buy that Auth and AntiCheat are not so synced.
But from my place where I am only given the information that I am allowed, I am not at this point able to trust Auth enough to login. There is more to consider than simply whether or not the AC is confused, (which is enough to consider anyway).


TOTAL SPECULATION:

The fact that there is something in Auth clearly broken makes it easy to believe there is a hole somewhere.
This is the internet where everything hates you and will destroy you just for fun.
If there is a hole in Auth that the Internet can find, it will use it to exploit and attack Auth names.
While I understand you can't tell me if this is the case or not, understand that I have to believe it is until I know it isn't.


<3

  • (4 Pages)
  • +
  • 1
  • 2
  • 3
  • 4
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Advertisement


Copyright © 1999-2024 Frozensand Games Limited  |  All rights reserved  |  Urban Terror™ and FrozenSand™ are trademarks of Frozensand Games Limited

Frozensand Games is a Limited company registered in England and Wales. Company Reg No: 10343942