Jump to content

  • Curse Sites
Become a Premium Member! Help
Latest News Article

MineAuth - open-source password system for private servers


  • Please log in to reply
7 replies to this topic

#1

graycode
    graycode

    Out of the Water

  • Members
  • 4 posts

Posted 04 March 2011 - 07:06 PM

MineAuth is an open-source solution for Minecraft server admins that enables your players to still connect securely (i.e., with password) even when minecraft.net is down.

http://www.mineauth.com

When minecraft.net is unavailable, players currently have the option of "not playing", or they can remove the authentication requirements of their private server and screen players based only on their user name (whitelist).  This is a supported mode for the software, known as "offline" mode, and is useful for setting up LAN games.

MineAuth aims to make offline mode more secure, giving admins an in-house, password-controlled access system for their private offline servers.

MineAuth illustration: Posted Image

MineAuth does not require any modification to the Minecraft client or server.  After a small setup step, your players will use Minecraft just as they normally would.

To manage user accounts, MineAuth exposes a web UI where users can change their passwords.  The web UI includes an admin tools panel for adding and deleting users, password rescue, and promoting other users to admin status.

MineAuth login page screenshot: Posted Image

Setup is easy!  A setup script is included with the download, and full, step-by-step instructions are provided in the User Guide on the main site.  If you discover any issues or run into trouble, feel free to send mail to support at graycode dot com.

At the moment, MineAuth supports only the old launcher (before the "new look" 1.3 launcher).  However, even if you don't update the launcher Minecraft will continue to update to the latest game files.  Your game experience should be unaffected.

Register or log in to remove.

#2

zombiemann
    zombiemann

    Redstone Miner

  • Curse Premium
  • Curse Premium
  • 594 posts

Posted 04 March 2011 - 07:28 PM

Something sounds a little fishy here.  If everything is above board and legit, I'm sorry but this is just my take on things.

A brand new user makes his first post as an advertisement for an application he has developed designed around bypassing the need for minecraft.net authentication.  Lots of room for abuse here. Not to mention if Notch wanted it to where the authentication wasn't needed, he would have coded it that way

Also it only works with the old launcher?  That sets off a big red flag for me, and anybody with a security conscious mindset.
zombiecraft.serverbeer.com - Permissions enabled home server, focusing on big builds

See what we are building here: http://zombiecraft.servebeer.com

#3

sansavarous
    sansavarous

    Lapis Lazuli Collector

  • Members
  • 1037 posts

Posted 04 March 2011 - 07:29 PM

Taking a quick look at the code it seems ligit however.

Old client is old. Everyone should use the new client.

Second, most people don't have a SQL database running on their systems.

Third most people don't have a website to run this from.

Fourth it's bad to edit the hosts file on a system. DNS is there for a reason. People may play on more then one server.

I applaud your efforts, however you are duplicating what exists and is provided by Mojang.

At this point any server that still uses 1.2 is out of date.

#4

graycode
    graycode

    Out of the Water

  • Members
  • 4 posts

Posted 04 March 2011 - 10:25 PM

zombiemann said:

A brand new user makes his first post as an advertisement for an application he has developed designed around bypassing the need for minecraft.net authentication.
Duly noted.  New user is new because my friends and I recently started playing the game. =) We ran into the issue described on the main page, developed a solution, and thought others might benefit from our efforts.

As far as the "advertisement" goes, it appeared from posts for other projects that this was a proper way to alert the community of a new project, gather feedback, and offer support:

    many more...

Your skepticism is understood - that's why it's all open-source!  Thank you for the feedback.

#5

zombiemann
    zombiemann

    Redstone Miner

  • Curse Premium
  • Curse Premium
  • 594 posts

Posted 04 March 2011 - 10:34 PM

Graycode:

The way you went about presenting your information wasn't bad per se..... just kind of suspicious.  Nothing personal intended.  The post itself is fine, but the fact that you are brand new to these forums combined with numerous phishing attempts and spam lately leads one to be wary.

I did take a quick browse through the code, and found nothing that stuck out as malicious, but again, as I said in my post: If Notch didn't want users authenticated, he wouldn't have built it into the code.  The software is still in Beta testing, and they are working on getting the bugs out of the authentication system.
zombiecraft.serverbeer.com - Permissions enabled home server, focusing on big builds

See what we are building here: http://zombiecraft.servebeer.com

#6

graycode
    graycode

    Out of the Water

  • Members
  • 4 posts

Posted 04 March 2011 - 10:37 PM

sansavarous said:

Old client is old. Everyone should use the new client.
...
At this point any server that still uses 1.2 is out of date.

Just to clarify, there is no need to use an old client nor an old server.  The only (temporary) requirement is that you stay on the old launcher.  All the actual game files will continue to be updated as normal.

But to address the larger point of your message, yes this is currently an issue that needs to be worked on.  Since we know there are others that share in this problem, rather than sitting on it we wanted to publish what we had so far, get some feedback and continue to iterate.

Though still fully functional, you're looking at the beginning of an open-source project. =) Thanks for the other feedback points as well.

#7

graycode
    graycode

    Out of the Water

  • Members
  • 4 posts

Posted 04 March 2011 - 11:12 PM

zombiemann said:

I did take a quick browse through the code, and found nothing that stuck out as malicious, but again, as I said in my post: If Notch didn't want users authenticated, he wouldn't have built it into the code.  The software is still in Beta testing, and they are working on getting the bugs out of the authentication system.
Zombiemann, thank you very much for looking through the code and reporting back.  It's interesting that folks won't hesitate to double-click SuperBlockEditor.exe, but as soon as you mention a project pertaining to security, even in source code form, it indeed triggers suspicion. =)  Your comments are very helpful.

I have a few responses to your comment about Notch's intentions:

First, one could argue that if Notch wanted users modifying maps, hacking inventories, and changing textures he would have provided the tools for us.  Minecraft has benefited greatly from a passionate community that has been willing to work alongside Mojang to improve the game experience.  We're just trying to add to this effort by solving the biggest hindrance we've personally experienced - the instability of minecraft.net.

Secondly, Notch has indeed provided a way for us to play Minecraft without access to minecraft.net authentication.  Offline mode exists both for clients and servers, with a built-in, Mojang-approved method for disabling server-side authentication.  However, as noted in that wiki page, this opens your server up to some security vulnerabilities.  We wanted a way to make our servers more secure when running in this mode.

MineAuth also brings new features not available in the stock game, such as the ability to have multiple characters on a server, and to be able to actually choose the names of your characters.

#8

zombiemann
    zombiemann

    Redstone Miner

  • Curse Premium
  • Curse Premium
  • 594 posts

Posted 04 March 2011 - 11:39 PM

Graycode:

You are right about the humor/irony present in the situation, but I can assure you I am not the type to blindly click on anything.  And I do thank you for making it so open.  If the source were not open I would not have bothered since this particular application works directly and admitedly with authentication..... Not much room for obscurity there if you catch my drift.  

Having gone through the source and found nothing concerning, I actually plan to test this application of a virtual set up, and would be willing to give it a review when I am done testing it.  

I don't think either of us are really in the mood for a debate on the propriety of this particular application. I agree that if minecraft.net were to be stabilized then the need for such applications would be eliminated.  And until such a time as Mojang gets that all sorted out, there will be a "market" for solutions of this nature.  What bothers me is it seems like this plug in would make it fairly easy for someone to set up a pirate server.  And piracy is something I am dead against, and as a software developer I am sure you can respect that.  

Like I said, I will be giving this a trial run and will report back my findings
zombiecraft.serverbeer.com - Permissions enabled home server, focusing on big builds

See what we are building here: http://zombiecraft.servebeer.com