From my point of view the easiest way to detect honorbuddy is to look at the client's open network connections. Like a "netstat /a" under windows...(even with non-priv. user rights)
So maybe your "a bit paranoid" online-auth.-system is a really bad idea?
So maybe your "a bit paranoid" online-auth.-system is a really bad idea?