PDA

View Full Version : password protection


ATRAIN
11-15-2004, 11:53 AM
Found on TWL, would this be that big of concern to EA?

"I found a security leek in the way mohpa stores passwords.

MOHPA is online cdkey, and you need to register with EA games to play multiplayer (as you all know). So you make an account name and password, launch your game, save your password so you don't have to enter it everytime, and login to play some MP... everything is fine right? ... Wrong.
MOHPA logs your username and password ( unencrypted ) to your unnamedsoldier.cfg in Documents and Settings. You were worried about people getting a hold of your cdkey with a keystealer before? What happens now when someone writes a sniffer that will log your configs? Hope you aren't using the same password for your paypal (or anything else for that matter)."

svoller
11-15-2004, 12:03 PM
Thanks for that tip, i checked out te file and sure enough in clear text was my ea username and password.

I removed those and wont tick the save details option again.

HLC_Moses
11-15-2004, 05:36 PM
The question has been posed to EA and we'll post an answer as soon as we have one!
For now, the general recommendation is to not save your login info, but even still, you still transmit it in clear text when you login, so that may be futile security measure.


~MOSES