Menu

#21 Prevent password collusion

New
woelpad
Security (1)
High
Defect
2017-03-27
2017-03-27
woelpad
No

There's currently no check against two powers or even the Master joining a game with the same password. This can lead to strange situations, such as a player being able to see all press because of his omniscient powers when sharing the Master's password. The solution is to refuse a player to join or take over with a password that's already in play and to notify the other player or the Master that his/her password has been compromised, urging to replace it.

Happened in game agentcarr, where the Master mixed up the privacy password with the player password, advicing everyone to join with the same password.

Discussion


Log in to post a comment.

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.