4 ms·
There's a lot of muds with web clients now a days. Telnet still seems to be the most popular though because most of the popular clients support it. If you're l
by raytopia 3y ago
There's a lot of muds with web clients now a days. Telnet still seems to be the most popular though because most of the popular clients support it.
If you're looking for something that isn't just text based Graphical Muds wmay be what you're looking for. For context they are the often times over looked link between muds and mmos.
I swear I remember reading something about connected mud servers but I can't remember it off of the top of my head unfortunately.
- jstarfish 3y agoTelnet's a shit option these days. No encryption. Webclients can be protected by HTTPS, and Evennia (for one) offers SSH.
- troad 3y agoGenuine question, but why would a MUD require encryption? Seems like a strange feature.
- cyanmagenta 3y agoCharacter login requires password, which is sent plaintext over telnet. Even if you get around that somehow, there are still concerns about session hijacking to steal someone’s in-game items and currency.
- troad 3y agoI suppose the threat vector seems incredibly low to me. Seems like a strange use of a capable hacker's time, in today's world of bitcoin and ransomware, to be preying on people's in-game currency / pets from ancient MUDs. Their saleability would seem to approach zero. Password reuse might be an issue, but in my experience people had their environments pre-configured to log in automatically, so a unique complex password would eliminate that risk. Personally, I think the complexity of implementing encryption for these services would outweigh the benefits. A big part of their appeal is the ease of setup and shell access.
- foobarian 3y agoI think you way, way underestimate MUD players :-)
- hhh 3y agossh is just as easy to use on the client side
- geoffmunn 3y agoI view it as an issue of best-practice password hygiene. Just because the stakes are low, and it's a hassle, doesn't mean you should skip it. The more you get used to implementing it, the easier it gets.
- o11c 3y agoSASL can secure the login without encrypting the whole session. And most other things benefit more from signing than from encryption, though I'm not sure how much support for this there is. That said, server software supporting SSH is getting common these days, so it might be a matter of just updating and/or reconfiguring the server. (It's difficult to make too general a statement about all servers though)
- wpm 3y agoWho’s looking though?
- night862 3y agoIn my opinion, its a critical feature. Consider that in 2024 even this public forum is accessed in an encrypted form by even non-logged in users. Here's an unstructured list of some of the reasons: Man in the middle attacks achieving remote code execution on client or server Surveillance and/or stalking Presence monitoring Psychological analysis (Maybe a user is drunk, maybe they're in a good or bad mood today.) Command injection or deletion Most people use services with no regard to any of these things and most will never be subject to them. If a precocious hacker teen, controlling spouse or parent, spyware/adware company, censorship application, oppressive state regime, rogue sysadmin, rival player or any such of the endless possible yet rare actors decide that your service is best suited to these ends, it is now more or less trivial to develop a plugin for their evil device. TERMINAL EMULATOR SECURITY ISSUES 2003 https://marc.info/?l=bugtraq&m=104612710031920&q=p3 https://marc.info/?l=bugtraq&m=104612710031920&q=p3
- jstarfish 3y agoMost people assume the threat is the FBI or the Chinese or something; it's not that MUDs are some high-value intelligence asset, but consider what anyone could glean by deploying a packet sniffer on your LAN and reading your traffic to/from it. That it's MUD traffic is immaterial. Same goes for local LLMs. Most UIs don't offer HTTPS enabled by default, so you're broadcasting your most intimate thoughts on the same network segment your malevolent stepchild uses. Apps make amateur spycraft for BPD-types easy.
- deleted 3y ago[deleted]