Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The proof is (relatively) trivial, since MS rolled out a chat-signing feature a while back. Basically all chat messages go through a similar handshake to the user-server-auth one when users first join a server. So if a chat message gets reported, MS can be pretty certain who did the reporting, and that the reported messages were, in fact, made by the reported party.

The real problem is the direct attack on the autonomy of server operators. Each Minecraft server is a separate community, and they should be left to their own devices to form their own internal expectations of behavior and speech. If Microsoft wants to moderate behavior on the servers they own (Realms) or actively advertise (Whatever's going on over in Bedrock), that's fine. But when I'm paying the server bill, the only interaction with MS I want is authentication (and maybe the skin server).



I think/hope any server running in cracked mode (online-mode set to false: https://minecraft.fandom.com/wiki/Server.properties) won't have this chat reporting. At least, it would surely be broken for anybody joining a cracked server with a cracked client. Maybe legit players on cracked servers could still be reported, if their client and the server both pass through the chat signatures.


As of right now, the chat signing (which was only used for blocking certain players' chat from appearing to you) can be disabled by the server alone, or in conjunction with the authentication.

It is unclear whether that will remain the status quo.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: