feat: upgrade stream cipher from XOR to AES-128-CTR
Replace the XOR obfuscation cipher with AES-128-CTR using the Windows BCrypt API. Key material grows from 16 to 32 bytes (16 AES key + 16 IV). All callers auto-adjust via StreamCipher::KEY_SIZE. No handshake or protocol changes needed beyond the larger MC|CKey payload.
This commit is contained in:
@@ -30,7 +30,7 @@ The dedicated server now includes a comprehensive security system to protect aga
|
||||
|
||||
| Key | Default | Description |
|
||||
|-----|---------|-------------|
|
||||
| `enable-stream-cipher` | `true` | Encrypt all game traffic with a per-session stream cipher |
|
||||
| `enable-stream-cipher` | `true` | Encrypt all game traffic with AES-128-CTR |
|
||||
| `require-secure-client` | `true` | Kick clients that don't complete the cipher handshake (blocks old clients) |
|
||||
| `require-challenge-token` | `false` | Require identity token verification to prevent XUID impersonation |
|
||||
| `proxy-protocol` | `false` | Parse PROXY protocol v1 headers for real client IPs behind a tunnel |
|
||||
|
||||
Reference in New Issue
Block a user