On September 24, 2026 11:43:58 GMT+02:00, "Anthony J. Bentley" 
<[email protected]> wrote:
>The problem with RCON is it's not a secure protocol. The traffic is
>unencrypted, there are no server fingerprints to prevent MITM, the only
>form of user authentication is a password that can be sniffed or brute
>forced. Minecraft listens on the same address for both RCON and normal
>client connections, so the only way to use it remotely securely is by
>locking things down with pf. IMO any configuration we could provide
>through an rc script would be significantly less secure than just
>running the server directly in tmux.
UX-wise, that is insufferable, at least in my book especially as a port made 
for everyone, and I'd find it more trouble than it's worth relative to just 
restricting RCON to localhost (I remember being able to do that within the 
server config directly but it's been a while and I'm wondering if that's 
present only in forks, not the vanilla server which much fewer people run 
anyway), not to mention that people coming from other operating systems where 
they may have already used it managed as a service before would find it a 
definite downgrade

Reply via email to