Latest Uploads
Invasion V ... tup screen

rychan

image-07-1 ... -20-59.jpg

Jayenkai

PixeLink - ... oween 2014

rockford

PixeLink P ... zle Editor

rockford

PixeLink

rockford

image-21-0 ... -21-29.jpg

Jayenkai

Forum Home

Open and secure?

UserMessage
Posted : Saturday, 25 February 2012, 04:01 | Permalink
Afr0


WW Entries : 3
Lately I've been working on a patching system for Project Dollhouse.
The system is awesome and works great, but last night I realized it has a gaping flaw - security.
The thing is, I want Project Dollhouse to remain 100% open source, and I am not willing to make any compromises there.
I want people to be able to run their own servers. But as of right now, there is no stopping people from leaking off each other's bandwidth.
Scenario:

Person A runs his own server, but is too cheap to provide a webserver for patching.
Person B runs his own server, including a webserver that hosts patches.
Person A directs PDPatcher to download patches from person B's server. This can be done either through a recompile or through a *.ini file.

Does anyone have any ideas to prevent this scenario?
My patch scripts can be found here.

Edit: I realize that providing patches, per definision, is a pretty open service that should and could neccessarily be accessed by anyone, but I'd just like some kind of insurance against systematic leaking, if possible...

-----
Afr0 Games

Project Dollhouse on Github - Please fork!
Homepage : http://www.afr0games.com
Posted : Saturday, 25 February 2012, 04:22 | Permalink | Mark Here
Afr0


WW Entries : 3
Oh!
I just realized I can instruct people to change 'patch.php' so that instead of accepting a URL of "?Version", it'll accept an entirely different URL.
That would also involve recompiling PDPatcher... I think I'll have to change the license, because the Mozilla License requires you to release any source modifications under the Mozilla License free of charge.

-----
Afr0 Games

Project Dollhouse on Github - Please fork!
Homepage : http://www.afr0games.com
Latest Posts
Black Friday Deals
Jayenkai Thu 09:36
What Have You Done - Nov 2014
Dabz Thu 06:57
Buying Bits vs Ready Made
rychan Thu 06:03
Doc's Return
Jayenkai Thu 04:31
Snow Thankyou
Jayenkai Thu 04:14
Festive Cheer : Xmas Cards
Kuron Wed 16:22
The Great SoCoder BakeOff
Kuron Wed 14:10
undefined reference to...
HoboBen Wed 12:44
Jurrasic World
Kuron Wed 08:53
Optimum Soup Stabilisation
rockford Tue 16:43
More

Latest Items
News : Newsletter #243
Dabz Thu 03:29
Dev-Diary : Scaling Back
rychan Wed 14:33
Showcase : Alpha Collexion
rychan Wed 06:23
Life : Health Update
rockford Thu 12:41
Blog : Powerball Hack
steve_ancell Tue 18:47
Showcase : GPS Fun Runner 3D
zzoom Tue 06:03
Hols : Advent Calendars
rychan Wed 04:56
Life : MIA until better
Jayenkai Mon 07:03
News : Newsletter #241
steve_ancell Thu 20:46
Snippet : Monkey Framework - HTML Layout
steve_ancell Thu 08:35
Woot : Update on hand issues
rychan Fri 10:00
News : Newsletter #240
steve_ancell Fri 05:29
Techy : My Newest Toys
Jayenkai Sun 04:16
News : Newsletter #239
Jayenkai Sat 05:34
Showcase : Preppie!
Jayenkai Fri 13:00
More

Who's Online
rychan
Thu, at 11:00
Jayenkai
Thu, at 10:48
HoboBen
Thu, at 10:21
Kuron
Thu, at 09:51
rockford
Thu, at 09:44
steve_ancell
Thu, at 09:27
blanko1324
Thu, at 08:35
Dabz
Thu, at 06:57
Krakatomato
Thu, at 05:48
spinal
Thu, at 05:12
Link to this page
Site : Jayenkai 2006-Infinity | MudChat's origins, BBCode's former life, Image Scaler.