Jump to content
rocket

About the Security Issues

Recommended Posts

Rocket handled it all pretty professionally, IMHO the admins responsible for the rollback overreacted and did a lot of stuff really badly. I shudder thinking about that "Security Notice ... annnn they trollllinnnn" post. That was awful and completely uninformative.

Obviously that post's author is not very fit for public communication in serious situations, unable to realize that the vast majority of users had no idea what he was talking about (he was referencing a pre-rollback announcement).

Rest of story is "oh well, shit happens, thank god for salted hashes".

Share this post


Link to post
Share on other sites

Hopefully auditing can be done at a moment's notice by the auditing team, mainly in order to prevent preemptive tampering by less-than-honest server admins trying to cover their tracks. If they had to actually request the temporary access from the server admins first, it may not do much good at catching bad server operators.

Share this post


Link to post
Share on other sites

Rocket handled it all pretty professionally' date=' IMHO the admins responsible for the rollback overreacted and did a lot of stuff really badly. I shudder thinking about that "Security Notice ... annnn they trollllinnnn" post. That was awful and completely uninformative.

Obviously that post's author is not very fit for public communication in serious situations, unable to realize that the vast majority of users had no idea what he was talking about (he was referencing a pre-rollback announcement).

Rest of story is "oh well, shit happens, thank god for salted hashes".

[/quote']

Tonic was there at the beginning of the incident, Rocket wasn't. As for the security notice from Tonic which did give information about what was going on (more so than Rocket's post) and lead me to scan my computer which found the malware so i thank Tonic for at least trying to help out.

Share this post


Link to post
Share on other sites

Rocket handled it all pretty professionally' date=' IMHO the admins responsible for the rollback overreacted and did a lot of stuff really badly. I shudder thinking about that "Security Notice ... annnn they trollllinnnn" post. That was awful and completely uninformative.

Obviously that post's author is not very fit for public communication in serious situations, unable to realize that the vast majority of users had no idea what he was talking about (he was referencing a pre-rollback announcement).

Rest of story is "oh well, shit happens, thank god for salted hashes".

[/quote']

Tonic was there at the beginning of the incident, Rocket wasn't. As for the security notice from Tonic which did give information about what was going on (more so than Rocket's post) and lead me to scan my computer which found the malware so i thank Tonic for at least trying to help out.

Done is done, time to move on. This was a learning experience.

Maybe next time it happens the announcement post could be called "Forums hacked - Accounts deleted" instead of "Forums/they trollinnnnnn". That way, people would think it is about accounts being deleted, not forums being trolled. I'm sure Tonic will go to his grave denying that it could have been worded better, but at least the info got out in the end.

Everything apart from the initial announcement was handled just fine, in my opinion.

Share this post


Link to post
Share on other sites

Done is done' date=' time to move on. This was a learning experience.

Maybe next time it happens the announcement post could be called "Forums hacked - Accounts deleted" instead of "Forums/they trollinnnnnn". That way, people would think it is about accounts being deleted, not forums being trolled. I'm sure Tonic will go to his grave denying that it could have been worded better, but at least the info got out in the end.

Everything apart from the initial announcement was handled just fine, in my opinion.

[/quote']

Indeed it was a learning experience, at least everything got straightened out in the end for the most part.

Share this post


Link to post
Share on other sites

Thank you for the much needed clarification :) I understand things like this happen. However, there is always a lesson to be learned as well :)

Share this post


Link to post
Share on other sites

That said, I hope security is taking high priority, and im glad to hear the situation has been fixed (i hope) id rather see updates stop while infrastructure is improved upon than trying to please the masses of people who dont seams to care what happens to there information.

I can tell you that as an Admin, I wish I had a better way to police my server. It's tough to deal with hackers. It seems that some admins are incredibly douchey and act like spoiled brats which puts some that generally want it to be a fair environment for everyone in a bad light. I hope admins are given some sort of tool to sniff out cheaters.

Share this post


Link to post
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now

×