Wayback Machinekoobas.hobune.stream
May JUN Jul
Previous capture 11 Next capture
2021 2022 2023
1 capture
11 Jun 22 - 11 Jun 22
sparklines
Close Help
  • Products
  • Solutions
  • Made with Unity
  • Learning
  • Support & Services
  • Community
  • Asset Store
  • Get Unity

UNITY ACCOUNT

You need a Unity Account to shop in the Online and Asset Stores, participate in the Unity Community and manage your license portfolio. Login Create account
  • Blog
  • Forums
  • Answers
  • Evangelists
  • User Groups
  • Beta Program
  • Advisory Panel

Navigation

  • Home
  • Products
  • Solutions
  • Made with Unity
  • Learning
  • Support & Services
  • Community
    • Blog
    • Forums
    • Answers
    • Evangelists
    • User Groups
    • Beta Program
    • Advisory Panel

Unity account

You need a Unity Account to shop in the Online and Asset Stores, participate in the Unity Community and manage your license portfolio. Login Create account

Language

  • Chinese
  • Spanish
  • Japanese
  • Korean
  • Portuguese
  • Ask a question
  • Spaces
    • Default
    • Help Room
    • META
    • Moderators
    • Topics
    • Questions
    • Users
    • Badges
  • Home /
avatar image
0
Question by andrfgs · Aug 06, 2015 at 12:40 AM · serverloginmmoauthentication

Is This Login Algoritm Secure For an MMO?

Hello, I am attempting to create a small online game in Unity much like minecraft which allows people to host their servers, but all validation is done on a central server. Since I'm struggling and don't know anything of PHP and HTTPS, I'm thinking of using a game build just as Authentification Server (with just a console) and then if everything is validated, it passes a token for the user to login in any playermade/gamemade servers (game build itself).

I'm thinking about sending information back and forth using ClientRPC/Commands using encryption. My algoritm right now is:

  1. Player sends hashed user id

  2. Server looks up if user exists, if so, it generates a SESSIONSALT, encrypts using hashed user password as key and sends it to user.

  3. User sends hash user + hash(SESSIONSALT + hash (pass + salt)) and sends it to server

  4. Server checks login and if successful sends a login token with: sessionTime, IP, Mac and hardwareSerials, username

What are the main vulnerabilities in such fashion? Is it acceptable security in an MMO?? In case not, can anyone point me somewhere to get me started in PHP (I tried multiple videos but none seems to be using secure methods)???

Comment
Add comment · Show 1
10 |3000 characters needed characters left characters exceeded
▼
  • Viewable by all users
  • Viewable by moderators
  • Viewable by moderators and the original poster
  • Advanced visibility
Viewable by all users
avatar image Dave-Carlile · Aug 06, 2015 at 12:41 AM 1
Share

Unless you are a security expert you should use an implementation that was created by security experts.

0 Replies

· Add your reply
  • Sort: 

Your answer

Hint: You can notify a user about this post by typing @username

Up to 2 attachments (including images) can be used with a maximum of 524.3 kB each and 1.0 MB total.

Follow this Question

Answers Answers and Comments

3 People are following this question.

avatar image avatar image avatar image

Related Questions

RPC to a single client 1 Answer

Running Unity 'headless' on server - Same license? 1 Answer

Unity Networking Question [Username/Pass] 0 Answers

Unity networking tutorial? 6 Answers

How to use already existing user credentials from my website as my applications login? 1 Answer


Enterprise
Social Q&A

Social
Subscribe on YouTube social-youtube Follow on LinkedIn social-linkedin Follow on Twitter social-twitter Follow on Facebook social-facebook Follow on Instagram social-instagram

Footer

  • Purchase
    • Products
    • Subscription
    • Asset Store
    • Unity Gear
    • Resellers
  • Education
    • Students
    • Educators
    • Certification
    • Learn
    • Center of Excellence
  • Download
    • Unity
    • Beta Program
  • Unity Labs
    • Labs
    • Publications
  • Resources
    • Learn platform
    • Community
    • Documentation
    • Unity QA
    • FAQ
    • Services Status
    • Connect
  • About Unity
    • About Us
    • Blog
    • Events
    • Careers
    • Contact
    • Press
    • Partners
    • Affiliates
    • Security
Copyright © 2020 Unity Technologies
  • Legal
  • Privacy Policy
  • Cookies
  • Do Not Sell My Personal Information
  • Cookies Settings
"Unity", Unity logos, and other Unity trademarks are trademarks or registered trademarks of Unity Technologies or its affiliates in the U.S. and elsewhere (more info here). Other names or brands are trademarks of their respective owners.
  • Anonymous
  • Sign in
  • Create
  • Ask a question
  • Spaces
  • Default
  • Help Room
  • META
  • Moderators
  • Explore
  • Topics
  • Questions
  • Users
  • Badges