| Sep 30 - 23:05:35 |
|
| Post Reply | Post new topic | Page: [ <<< - < ] 1 2 3 4 [ > - >>> ] |
| System Wide Password Change. | Started by: Squishy on Sep 04, '09 13:41 |
|
ColdBloodedMafianatr, Your total lack of grammar disgusts me almost as much as your lack of righteousness. |
|
| Reply by: Kates at Sep 04, '09 20:01 | |
| Report Post | Tip |
|
My apologies, as I meant to continue my thoughts and actually address the matter at hand. I can hardly imagine that anyone would debate that both a grievous act of negligence and a potentially malicious act of security-theft have occurred. Debating these things will likely accomplish nothing- this situation has been handled excellently since the incident took place and I have no doubt that the proper course will be taken. For those of us who have no say in what will come and no new insights to offer, words are wasted here. |
|
| Reply by: Kates at Sep 04, '09 20:04 | |
| Report Post | Tip |
|
Actually, I agree with "~T~" . Whilst I don't doubt that Fridge's intentions were not malicious, it is important to take this responsibility away from the admins. Simply coding a piece of login software that checked for both alpha and numeric qualities would ensure this type of mistake did not happen again. |
|
| Reply by: HairyBaby at Sep 04, '09 20:34 | |
| Report Post | Tip |
|
Normally I wouldn't weigh in on something like this but in this case I will. Regardless of the obvious breach of trust suffered here by Fridge, it also stands to reason that if you are an admin of a site with high level access, you don't just use that access anywhere. Ideally, you'd use your own, secure machine and constantly be clearing cache and cookies if anyone else used the machine with you. In other words, you wouldn't risk using a machine you don't own/aren't familiar with. Because there is no guarantee that even if Fridge *had* logged out that cached information would still be recoverable. |
|
| Reply by: Naomi at Sep 04, '09 21:34 | |
| Report Post | Tip |
|
The day I learned that even a single individual had access to look at your password, I immediately changed my password for this site to a different one than all my other passwords. It's not that I don't trust the admins to act in good faith, it's that mistakes like this invariably happen. It's hard to blame Fridge for not being perfect, and it's hard to blame stjimmy for being tempted by something which admittedly would be very hard to resist. Personally, I'd prefer if this be a learning experience and the password database were made inaccessible to anyone; Boaby's idea of an automated process to screen passwords to be more secure is an excellent one. |
|
| Reply by: Lucretia_Borgia at Sep 04, '09 21:48 | |
| Report Post | Tip |
|
Before People keep saying that this happened on there pc it did not. I used my access on my own laptop. It was with my laptop that things got breached. I fucked up and made a mistake. A mistake that I will regret for a long time. I cherished my position as an admin but regret having to give my ability to assist the mafiareturns team and its players. |
|
| Reply by: Cory at Sep 04, '09 23:13 | |
| Report Post | Tip |
There are no fool proof methods out there. NOTHING is fool proof. |
|
| Reply by: Anubis at Sep 04, '09 23:23 | |
| Report Post | Tip |
|
This StJimmy guy sounds like a real wiener. I assume he's been permanently banned? |
|
| Reply by: Alfieri at Sep 05, '09 01:07 | |
| Report Post | Tip |
|
Scratches his head What the hell are these people talking about... |
|
| Reply by: SubSailorSteve at Sep 05, '09 01:39 | |
| Report Post | Tip |
|
Good: This was handled quickly. I'm glad. Bad: People are talkign about password requirements. Honestly, I for one am sick of people whiigng about my password security at any site. Ugly: Stjimmy's a tool. Fridge (Cory) has been demoted, and trust was wounded. |
|
| Reply by: Michael_Desatio at Sep 05, '09 03:04 | |
| Report Post | Tip |
|
I would just like to add my piece here. Yes a mistake was mde by Fridge, Yes StJimmy should not have been able to acess the system in the first place and even tho he saw the oppertunity he should not have used it.Potentially this could have caused untold damage, Not just by acessing user accounts but because it was clearly an admin account so there would have been more permissions in place. Lets face it, how many people use the same password for there paypal, the same paypal they use to donate to the site. This in turn contains your credit card information. But in my opinion squishy and the other admins dealt with this quickly and effectivley, I for one thank them for this. You might be reading this and think "what is she mad she isnt blaming or slating the people responsible" I am blaming them, and we can slate them all week if we want. but the bigger issue in my opinion is that altho our details were comprimised, we were informaed as soon as it would have been possible and we were all prompted to change our passwords. They didnt have to give us this information, we could have been told it was a bug or an error and we was to change them. but they chose to be honest and tell us the truth. When you register on a website you are petentially giving your information to the person who owns the site and trusting them with it, yes in most cases it is encrypted and in this case some admins have the abitlity to see the unencrypted passwords. Yes it was a ball ache changing all of my passwords elsewere, but i actually think this might have been the wake up call i needed, as I never regarded my internet security to be a big thing. So in conclusion. Thank you to the admins for rectifying the issue so quickly and being open and honest, in my opinion this makes me trust you with my passwords and other details so much more. |
|
| Reply by: lorrie at Sep 05, '09 03:30 | |
| Report Post | Tip |
True, but I think he has a good point. Check the password on selection to see if it is difficult enough (numbers, letters, and possibly caps), and then permanently encrypt it. Password encryptions can then be compared which works almost as well (as long as you're not using MD5). True, there is one situation where this would not be the most efficient means of comparing passwords, but I think real-life privacy and security of (more than one thousand instances of) personal information is much more important than whether or not so-and-so has more than one online game account. |
|
| Reply by: Awesome at Sep 05, '09 03:32 | |
| Report Post | Tip |
|
Thanks for letting us all know about this situation and being honest, its good to know we are in sensible hands. |
|
| Reply by: Rufus at Sep 05, '09 10:36 | |
| Report Post | Tip |
|
What is all this talk of passwords, encryptions and websites? I do believe you've all gone crazy. |
|
| Reply by: HannibalLecter at Sep 05, '09 14:14 | |
| Report Post | Tip |
I accept that. However, I fail to see how passwords being visible really gives any advantage (including checking for dupes) on the security front, but it does give numerous drawbacks. Large ones as we've seen here. In my day to day job, I work on at least a dozen large database applications. NONE of them have visible user passwords and I have full database access, code access etc etc. I'm not getting at you guys, so apologies if it comes across that way, it's merely concern. |
|
| Reply by: BoabyWanKenobi at Sep 06, '09 07:43 | |
| Report Post | Tip |
|
I agree with TesleR! You can do it!!! |
|
| Reply by: y0h at Sep 06, '09 08:23 | |
| Report Post | Tip |
It does help, but I agree; the drawbacks are too great. Real-life security trumps Mafia Returns security every time. |
|
| Reply by: Awesome at Sep 06, '09 08:27 | |
| Report Post | Tip |
|
A couple of points here: a) Is it PURELY passwords that are at risk. Ie. is there any risk to paypal accounts/payment records. I ask this not because I assume there is (in fact the opposite) but better to be safe than sorry. b) How can Fridge NOT be held responsible for this? I KNOW he is a human being and we all make mistakes (in fact I recently used the same argument with my boss earlier this year when discussing the potential sacking of another employee). But at the end of the day he is still responsible. Like it or not (and I don't, I really REALLY don't) people have to pay for their mistakes - its how life is. By the sound of things Fridge has already paid and, as it has already been said, its a difficult one. Personally I think it is obvious that StJimmy is the most majorly at fault. He exploited something which he shouldn't have. So obviously should be given a hugely harsh "sentence". I dont agree that "99%" of the userbase wouldnt choose to exploit this, because like it or not people are curious and 'power corrupts absolutely'. But, it HAS to be shown that risking this negligence if given unexpected power has massive consequences. However it should also be shown to the other admins that mistakes are hugely damaging to the game and to its players. If Fridge has been demoted then fine, I think that is right at least for a period of time. Thing is though you learn from your mistakes and he, as far as I remember, is a huge asset (not HAS - i wouldnt know). I would give him my full support believing (allbeit blindly) that he probably feels hugely stupid/guilty/remorseful and I don't think for a second the same thing would happen to him again - again blindly. I firmly DO believe (probably NOT so blindly) that assuming he has learned from a mistake that could so easily have made by anyone (but wasn't remember!) Fridge is more of an asset as a fully fledged admin then that of anything less... |
|
| Reply by: Benvolio at Sep 06, '09 17:57 | |
| Report Post | Tip |
|
I am with Boaby on this one. I find it quiet astonishing that unencrypted passwords are stored for access by anyone let alone high ranked assistants/administrators, I would hope that after this situation some time is spent and this practice is changed so only encypted passwords are seen by anyone. Are email accounts also viewable by the same token? |
|
| Reply by: El_Nino at Sep 06, '09 18:08 | |
| Report Post | Tip |
|
I am on my own side. I for one will change my password back to the old one as soon as I can. I trust StJimmy, even if he has royally fucked you all. I believe that he won't touch anything having to do with me. Oh, and whoever made the comment about his wife... Completely uncalled for |
|
| Reply by: JamesTiberiusKirk at Sep 06, '09 18:22 | |
| Report Post | Tip |
| Post Reply | View All Threads | Page: [ <<< - < ] 1 2 3 4 [ > - >>> ] |
Minimum $20,000