top of page

Passwords, Rate Limits, and Accounts Without Email

Writer: Marcel Dütscher
Marcel Dütscher
Jul 6
1 min read

Updated: Jul 10

Blocks Beyond The Stars is also played by children. That shapes not only the game design, but also the security engineering behind it. Three examples.


Accounts without email — on purpose. A player account with us doesn't require an email address. That's not a missing feature, it's a decision: we want as little personal data as possible, especially from young players. What we don't store can't get lost. (The honest flip side: there is no "forgot password" via email as a result — we communicate that openly.)


World passwords, done right. If you protect your world, your password is never stored in plaintext, but as a PBKDF2 hash — even we can't read it. The password is checked before the world is woken up, so strangers can't spin up other people's worlds through mere join attempts. And after ten failed attempts in 15 minutes there's a cooldown against brute-forcing.


Automated guardians. Our code runs through CodeQL, GitHub's static security analysis. It has actually caught us: a language cookie was initially set without the Secure and HttpOnly flags — sounds harmless, but needlessly attackable. Fixed, and since then we look at every new alert.


The common thread: security for us isn't a department, it's a series of small, consistent decisions. For a game you give to your own child, that's the only way that feels right.

Recent Posts

See All

Comments


bottom of page