News

200 users signed up - a serious talk about password security

The good news

The website has hit 200 signed up users after only 20 days! That is amazing and I never expected it to grow that quick.

FYI, @chp2001 is user #200.

The bad news

Now you're probably wondering why the title of this blog post contains something about password security.
We have ran a little security experiment on the website, and I don't like the results at all!

When you signed up on the website, the website automatically uses your IGN or email address and the password you used for registration to test if a login to mojang is successful, or not.
It uses the same way to login the Minecraft launcher uses, as documented here. (warning: nerd stuff)
In case you're scared now, that is actually what we wanted to achieve. The passwords are not stored, however.

DO NOT RE-USE ANY PASSWORDS!

If it isn't yet clear to you why you shouldn't re-use your minecraft any password on redstoner's website anywhere else again, here are just a few examples:

  • If we wanted to, we could store the passwords and claim your account
  • We could also assume that you probably use the same password for facebook, gmail, minecraft forums, ... and claim those accounts, too
  • If we would (be stupid enough to) store your passwords in plain text and someone gains access to our database,
    not only we would have your passwords, but the hackers would as well!
  • If any of the services where you're using this password gets hacked, they can claim your account on redstoner's website, too.

You are probably re-using your password because you cannot come up with any other ones or can't remember too many passwords.
There is a solution to this problem. There are lots of programs called Password manager or Password database which store all your account details + passwords.
All you need to remember is a (really strong) master password to unlock the database.
Many of them will also allow you to generate random passwords.
I use KeePassX to handle this, and it handles it pretty well.
It runs on many systems including mobile phones and you can use dropbox or the like to access it from anywhere (dropbox can't see your passwords because they don't know the master password).

Finally, here's a chart that shows the date on the X-Axis and the number of registrations (blue) plus the number of players who re-used their minecraft login password (red).

chart
Here is a png version in case the chart above doesn't work.

This chart makes me sad. Really sad.
We have a total of 200 registered users, 53 of them re-used their password. That is a whopping 26.5%!
A Minecraft account costs 26.95$. I could have claimed accounts worth over 1428$ in 20 days!

Those who re-used their password got an instant notification on the website and a warning in their registration email.
I hope I was able to explain why it's a bad idea to re-use passwords. Please change your passwords wherever you use them, now!

Feel free to leave your questions in the comments!

2 New plugins: ChatGroups and ForceField!

We've added 2 new plugins onto the server, one which you will be able to use to chat with certain players, and another which more specific users will be able to use in order to play with no players annoying them, for example people like Mumbo Jumbo, or fennoman if he's livestreaming.

For chatgroups, you can use /cg to control your chatgroup. If you want to chat to your chatgroup, use :, but you can also use /cgt to toggle chatgroup messages and global server messages.
Here's some more info on /cg:
Chatgroup help
This plugin was made by our godfather, sheep! :D

For forcefield, this pic should explain:
Forcefield help

the forcefield just keeps other players on distance. Eventually you can whitelist certain players so they can enter your forcefield, and build with you.
Forcefield is not likely to be given to you, unless you're hoarded by players, and just to clarify, I'm not hoarded, I just wanted to make a plugin :)
forcefield is my first kinda complicated plugin written in python, so please give me some feedback! :)

Reason for our downtime a few hours ago

Those were all TNT carts:
tnt carts

Default WorldEdit Selection Limit Changed to 10201

Most people with worldedit were limited to 10000 blocks in one go. I thought this was a bit unlucky, since the plots are 101x101 which is 10201 when squared. So I changed it to 10201. Everyone with worldedit can change their plot floor with 1 command, and without shifting their selection! :)
Thanks @willetaking for testing it out! ;)

AnswerBot

Today me and a few otheres were a little annoyed from people asking the same questions over and over again.
I decided to write a little bot that recognizes questions answered in our FAQ, hides the message from chat and displays a notice to the sender.
Not 1 hour later it was done, it looks like this:

clear plot

I hope this helps everyone to not get annoyed by noobs and to find answers quick.

Thanks @Pigglypops for playing dumb and testing.

Please leave some feedback or false positives in the comments.

Update

  • The bot will only affect any ranks below builder
  • More newbie-questions are now filtered

New rank: Helper!

We decided to add a new rank to help the staff members with assisting players in need of help (e.g. WorldEdit).

Our first 2 helpers are @yop_tropix and @KPkiller1671 (Nickname KPkrisps). In chat, their name will be shown in gold, like this:
Picture of Helper in chat

Permissions

Helpers can:

  • kick
  • tempban
  • read and resolve /reports
  • use staff chat
  • teleport themselves or other players
  • find lag using a few tools

they do not yet have access to all ingame commands, we find that a bit of a big step from trusted to moderator.

You can regard helpers as mods on trial, and of course feel free to ask them for help, thats in fact what they have their rank for! (Note that they can't help you on every topic, like promoting.)

As with all other ranks besides mod and admin, they will (currently) be shown as normal users on the website.

More info on ranks here.

Username mentioning

You can now mention users on the website.
Simply type @ followed by their IGN and they'll receive a mail (unless disabled in their notification settings)!

The editor also supports automatic suggestions for usernames as you type them:
mentioning gif

Credit where credit is due:
The javascript code that places the suggestions in the editor is a plugin from Amir Harel, which has been modified a little bit by myself.

Enjoy!

Cycle plugin

We have a new plugin, and it's increibly useful!

When you scroll your item hotbar from left to right or vice versa, it will cycle the hotbar items with your inventory!
You don't need to use a command or anything.

Here's how it looks like:
cycle screenshot

You can fill it with all 4 lines of items, empty lines in your inventory are skipped.

This plugin is enabled by default.
If you don't like this, for whatever reason, you can disable it:
/cycle <on|off>
But please leave a comment why you do not like it!

Update

Try this plugin with /kit rs to fill your inventory redstone blocks and /kit bus for color coding (and a sign)!

Update 2

It's no longer switching when you sneak. Good idea Traks!

Update 3

It's no longer switching in survival due to possibly losing vital items on your hotbar.

Piggly & Sheep

Welcome to the new website!

After months of hard work from sheep, and countless hours of testing by the staff, Redstoner.com is finally done!
As you can see in the menu bar, we have a News blog, Info pages Forums, and more.
The website should also work perfectly fine on Smartphones.
Definitely go check out the Info pages!

Other Changes

We have a new spawn:

new spawn
Simply jump off the edges to "fall" into a World.
Inside the Piston you'll find the FAQ and a list of donators further down.

Survival world

We have decided to make the Survival world griefing allowed.

This change was made to make it really "survival", create a bit more fun, and challenge for everyone.

Plugins

We have recently worked (and are still working) on some custom plugins. Some of these are a bit older, but we think not many are aware of them, so we tell you anyway. We also have an info page about plugins with more details.

  • ChatGroups > Lets you create a group chat with multiple users.
  • Reports > Report problems to the staff!
  • SayLol > Broadcast funny messages
  • Mention > Highlights your username in chat and makes a sound
  • ShearSheep > Try it :)

Website registration

The registration is fairly simple, but requires one extra step to make sure all players are really from the server and aren't bots or are impersonating other people.

See this info page about Signing up.


If you still have questions, read the Website FAQ or leave a comment after you signed up!

The Redstoner staff team