Page 1 of 1

Question to developers about network security

Posted: Thu Feb 11, 2016 12:26 pm
by Oribrost
Recently we have begun playing OpenRA at our workplace. I was asking our sysadmin whether it would be ok to play on the internet and not only on the LAN, and he said that he is worried that players could see our IP and hack us.

My question is as follows:
1) when I enter a game, who can see my IP? All players? Or only the server?
2) Which of the servers "official", i.e. owned by OpenRA developers and therefore it is likely that its owner will not use the IP information against us in any way.
3) If I understand correctly, connecting to an official server poses no more security risk than opening the OpenRA website, is this correct?

Posted: Thu Feb 11, 2016 3:19 pm
by klaas
Oribrost wrote: My question is as follows:
1) when I enter a game, who can see my IP? All players? Or only the server?
2) Which of the servers "official", i.e. owned by OpenRA developers and therefore it is likely that its owner will not use the IP information against us in any way.
3) If I understand correctly, connecting to an official server poses no more security risk than opening the OpenRA website, is this correct?
1) All players can see your IP. I think this is not absolutely necessary, and I'm sure that at least one server doesn't show IPs in-game. I'm not sure if they don't get saved anywhere in the replay though.
2) There is no "official" game server, all servers are either maintained by individuals, or by gaming communities/ websites. The masterserver is "official", but still maintained by individuals.
3) No idea, AFAIK connecting to a website allows the same sort of information exchange.This does not mean browsing is safe. Many people disallow scripts to run in their browser for this reason. I don't know how safe OpenRA is at the moment, but you cannot connect to a server outside of your own network, and be 100% safe.

Posted: Thu Feb 11, 2016 4:36 pm
by Graion Dilach
No, the game enforces players to reveal their IP. Yes I also have security concerns about this, but so far the core devs consider this POV necessary as a defense of "nick abusing" due to not having a centralized account service.

Posted: Thu Feb 11, 2016 7:47 pm
by klaas
Graion Dilach wrote: No, the game enforces players to reveal their IP. Yes I also have security concerns about this, but so far the core devs consider this POV necessary as a defense of "nick abusing" due to not having a centralized account service.
Creating a problem while solving another, didn't know this. I remember there is a server that doesn't show IPs in the lobby, saying locations are unknown.