| Poll Comments |
 |
 |
 |
 |
| |
 |
| | Sorry DjObscene you have to vote from the front page of the site. The link just links to the results. |
|
 |
| | I couldn't find the "not sufficiently involved to pass judgement" button so went for Other |
|
 |
| | Wasn't redore the one who found and reported the exploit? If he finds a way to obtain all passwords and E-mails, and chooses to report it rather than harvest it, isn't that a good thing? |
|
 |
| Yes that would have been good. But all the accounts were harvested, and logins were made using harvested accounts, pm's read, forums viewed and users on IRC had their accounts ghosted.
The general feeling was, we did not feel comfortable keeping quiet about this when there seemed (to us) a high risk of the information being misused. |
|
 |
| OSIX provides challenges, the OSIX site itself is not and should not be a target, never the less if a user does find a security hole it should be tested (minimally) to confirm findings and then reported to OSIX staff who should then take steps to fix it.
OSIX Staff did fall on their face here:
"As the user had come to us initially and privately reported the problem we had thought that it may not be required to reset and warn everyone, especially as the user had been a fairly active member of the community." - And it seems a harsh lesson was learned - OSIX staff should take this opportunity to upgrade the captcha system as the level of butthurt will probably spiral into DDoS and forum flooding.
My view on this is, ban him, if he wants to use a proxy to come back then that's a little sad but ultimately trivial to add a ban on used proxy servers. |
|
 |
| | Give praise. He's a hacker, not a cracker, and he told you guys about it. That's a net positive. |
|
 |
| | You've been trying for six hours, and you've only just realised you can request a new password? |
|
 |
| It's some funny shit after all :-)
Ok be honest guys, so you are saying non of us, ever tried to hack the site, nobody?, not even silly javascript or sql injection, just to check if that would work?
Heh
The only difference is that he succeed... |
|
 |
 |
 |
 |