calgaryguy
Chieftain
- Joined
- Mar 13, 2012
- Messages
- 1
I'm playing a hotseat game with five other people and discovered something interesting.
I found that if I search the savegame file (using notepad) for my password, I also discover the passwords of all the other players.
Heheh, so now I have an advantage due to my 'spy abilities'
Knowing the other players passwords allows me to cycle through all the players moves and see what their status is, their relationships with other players, trade aggreements, etc.
It also allows me review the entire map and figure out everybody's relative location.
I can see if somebody is sending an army my way and prepare for it.
Of course this is a security flaw, which may not seem like a big deal but here's the thing.
Most people use the same password for everything - Facebook, Gmail, domain logins, etc.
So now I can hack into the private aspects of their online life.
I'm not going to do that, but the point is you should use an entirely unique password for multiplayer games. I'm sure that Civ5 makers will someday learn how to encrypt passwords and this will no longer be an issue.
I found that if I search the savegame file (using notepad) for my password, I also discover the passwords of all the other players.
Heheh, so now I have an advantage due to my 'spy abilities'

Knowing the other players passwords allows me to cycle through all the players moves and see what their status is, their relationships with other players, trade aggreements, etc.
It also allows me review the entire map and figure out everybody's relative location.
I can see if somebody is sending an army my way and prepare for it.
Of course this is a security flaw, which may not seem like a big deal but here's the thing.
Most people use the same password for everything - Facebook, Gmail, domain logins, etc.
So now I can hack into the private aspects of their online life.
I'm not going to do that, but the point is you should use an entirely unique password for multiplayer games. I'm sure that Civ5 makers will someday learn how to encrypt passwords and this will no longer be an issue.
