Original Post
Just wanted to ask if anyone has any pointers with my idea for login. I'm going to use a WCF webservice over SSL to do the login system. The client will make the connection, BCrypt the pw on the client side, send the username and BCrypt'd pw to the server via the web service, have the server web service check against the database and return FAILURE if incorrect match OR a GUID as the session ID if successful match. After that all other data will be sent over a non encrypted channel as it's not critical.
Is this enough security around this? Am I missing any holes? My biggest fear with this stuff is I miss a big security hole and something gets compromised and people sue me if the game becomes popular enough. Seems you could go from hero to zero in a matter of hours with online games and security around them.
Is this enough security around this? Am I missing any holes? My biggest fear with this stuff is I miss a big security hole and something gets compromised and people sue me if the game becomes popular enough. Seems you could go from hero to zero in a matter of hours with online games and security around them.