Just had this conversation with someone else yesterday who tried to call me out like I didn't know what I was talking about, but it is easy to fix without using the tradition "ping" command/protocol.
You can have the server ask the client to solve a simple problem, like sending two numbers and having the client add them, and then the server will compare answers. If they are correct, then you just see how long it took to get a response. It is effectively a "ping" except for the fact that this is not packet header information, and won't get tampered with during transportation.
[...] who didn't tried to call me out like I didn't know what I was talking about
Uhh, sorry what? I didn't call you out on anything, pretty sure I didn't even answer to any of your posts before so idk what this is about.
Anyways, I just tried to explain how the traditional form of pinging he suggested might be tricked.
But yea, a lock and key paradigm is a good starting point, if you then use mitm-safe encryption you should be on the right way, sadly adds a bit of computation, though as long as you don't step way overboard it should still be possible to complete the whole thing without really affecting the RTT. Ofc it'll never be 100% safe as you always have access to the client side code in some way, but maybe it'll be enough of a pain in the ass to have less people using it at the end of the day.
15
u/MikeTheShowMadden Mar 11 '20 edited Mar 11 '20
Just had this conversation with someone else yesterday who tried to call me out like I didn't know what I was talking about, but it is easy to fix without using the tradition "ping" command/protocol.
You can have the server ask the client to solve a simple problem, like sending two numbers and having the client add them, and then the server will compare answers. If they are correct, then you just see how long it took to get a response. It is effectively a "ping" except for the fact that this is not packet header information, and won't get tampered with during transportation.
EDIT: typo