
These forums are CLOSED. Please visit the new forums HERE
"Fixed An Exploit" - whaaaaa? |
|
Burke Prefect
Cafe Owner, Superhero
Join date: 29 Oct 2004
Posts: 2,785
|
07-18-2005 17:40
I'm guessing that my CTRL-ALT-SMITE code isn't out in the open. Or LL would be spending more time making a patch.
![]() |
Enabran Templar
Capitalist Pig
![]() Join date: 26 Aug 2004
Posts: 4,506
|
07-18-2005 17:41
oh come on, seburo is no big deal. multithreaded rezzing of bullets .. la la. Is there anyone in Second Life whom you do respect, or do you trash the efforts of everyone equally? _____________________
Furthermore, as Second Life goes to the Metaverse, and this becomes an open platform, Linden Lab risks lawsuit in court and [attachment culling] will, I repeat WILL be reverse in court. Second Life Forums: Who needs Reason when you can use bold tags? |
Dianne Mechanique
Back from the Dead
![]() Join date: 28 Mar 2005
Posts: 2,648
|
07-18-2005 17:45
...Though, could be an ex employee.... _____________________
.
black art furniture & classic clothing =================== Black in Neufreistadt Black @ ONE Black @ www.SLBoutique.com . |
blaze Spinnaker
1/2 Serious
Join date: 12 Aug 2004
Posts: 5,898
|
07-18-2005 17:50
actually, mr fairplay's poker hand evaluation code.
but, that doesn't seem to be in the list.. _____________________
Taken from The last paragraph on pg. 16 of Cory Ondrejka's paper "Changing Realities: User Creation, Communication, and Innovation in Digital Worlds :
"User-created content takes the idea of leveraging player opinions a step further by allowing them to effectively prototype new ideas and features. Developers can then measure which new concepts most improve the products and incorporate them into the game in future patches." |
Dianne Mechanique
Back from the Dead
![]() Join date: 28 Mar 2005
Posts: 2,648
|
07-18-2005 17:53
Below is the text of Chris Linden's response to my request for a statement regarding today's events, as posted in the Hotline. There must be a list somewhere of who is reading or has looked at the thread, your criminal is on that list. . PS - I used "man" on purpose. _____________________
.
black art furniture & classic clothing =================== Black in Neufreistadt Black @ ONE Black @ www.SLBoutique.com . |
Burke Prefect
Cafe Owner, Superhero
Join date: 29 Oct 2004
Posts: 2,785
|
07-18-2005 17:54
ME: My gun has MULTI-THREADING!!!
Blaze: But can it play DOOM 3!?!!? ME: *looks at gun, sadly.* No, no it can't. ... *perks up* but I can SHOOT YOU REALL GOOD! *chases Blaze around screaming 'Dance, piggy, dance!"* Yeah, open-sourcing things that aren't meant to be open can be dangerous. God knows I'm modding something that was unintentionally opensourced (apparently a very, VERY messy beta of something) for the greater... er, good. If I can find the person who made it I'd toss him some change. |
Chip Midnight
ate my baby!
![]() Join date: 1 May 2003
Posts: 10,231
|
07-18-2005 17:55
I'll never understand the hacker mentality. If whoever did this had the technical savvy to pull it off they could have used their skills to do their own cool stuff instead of using it to fuck over other people and destroy their hard work. It's truly amazing how much some people suck. I hope LL is able to find the jackass and smack him down hard.
_____________________
![]() My other hobby: www.live365.com/stations/chip_midnight |
Aren Vindaloo
Registered User
Join date: 30 Jun 2004
Posts: 3
|
07-18-2005 17:55
PS - I used "man" on purpose. Because you're sexist and want the world to know it? |
Chip Midnight
ate my baby!
![]() Join date: 1 May 2003
Posts: 10,231
|
07-18-2005 17:58
Because you're sexist and want the world to know it? Nah, because she's right and she knows it. How many female hackers or virus writers have been arrested and jailed? I don't know of any. _____________________
![]() My other hobby: www.live365.com/stations/chip_midnight |
Aren Vindaloo
Registered User
Join date: 30 Jun 2004
Posts: 3
|
07-18-2005 17:59
Nah, because she's right and she knows it. How many female hackers or virus writers have been arrested and jailed? I don't know of any. Still a terribly ignorant statement. Insulting, too. Oh, right. Math is hard. I forgot. |
Lo Jacobs
Awesome Possum
![]() Join date: 28 May 2004
Posts: 2,734
|
07-18-2005 18:00
Still a terribly ignorant statement. Insulting, too. Oh, right. Math is hard. I forgot. LOL who cares? _____________________
http://churchofluxe.com/Luster
![]() |
Pendari Lorentz
Senior Member
Join date: 5 Sep 2003
Posts: 4,372
|
07-18-2005 18:01
Because you're sexist and want the world to know it? I'm sure she has a better explanation. _____________________
*hugs everyone*
|
Aren Vindaloo
Registered User
Join date: 30 Jun 2004
Posts: 3
|
07-18-2005 18:03
LOL who cares? I just find it funny how if someone had done something negative and 'stereotypically female' and someone said 'heh it's obviously a woman' in a rather insulting way, everyone would be crawling all over them shouting sexism, but it doesn't go the other way. But we sure do love our double standards. However, I don't want to hijack this thread, so I'll leave it drop. It wasn't an appropriate time or place. I apologize for this interruption, we return to your regularly scheduled thread. |
Siggy Romulus
DILLIGAF
![]() Join date: 22 Sep 2003
Posts: 5,711
|
07-18-2005 18:04
Is there anyone in Second Life whom you do respect, or do you trash the efforts of everyone equally? Everyone else says it's bad - take it as given blaze will say it's good or inconsequential. Same old same old... and fairly predictable. Of course the point he overlooks about re-writing is that it is obviously faster to drag a script, or even cut/paste than it is to re-write or work out for yourself. And that, the investment of time and learning, is what's being stolen - what you make at the end of the tunnel is the payoff for the time you put in. The knowledge gained and sometimes profit made for having the discipline to research, work, think, and create is the reward.. and I think the creator, not some random bozo, is entitled to that reward. Siggy. _____________________
The Second Life forums are living proof as to why it's illegal for people to have sex with farm animals.
I, for one, am highly un-helped by this thread |
Shaun Altman
Fund Manager
![]() Join date: 11 Dec 2004
Posts: 1,011
|
07-18-2005 18:04
i first hope that now the permissions are granted by the SERVER and not the client there was a flaw it seems Yeah really. What were they THINKING????????????? -Shaun |
Frans Charming
You only need one Frans
![]() Join date: 28 Jan 2005
Posts: 1,847
|
07-18-2005 18:05
Nah, because she's right and she knows it. How many female hackers or virus writers have been arrested and jailed? I don't know of any. That's because they are too smart to get caught. ![]() _____________________
|
nimrod Yaffle
Cavemen are people too...
![]() Join date: 15 Nov 2004
Posts: 3,146
|
07-18-2005 18:12
Soooo, what IS the link to that website with the scripts anyways? Not that _I_ would want them or anything!
|
Aliasi Stonebender
Return of Catbread
![]() Join date: 30 Jan 2005
Posts: 1,858
|
07-18-2005 18:17
Nah, because she's right and she knows it. How many female hackers or virus writers have been arrested and jailed? I don't know of any. Quite a few, actually. Although, technically speaking, most of 'em were phone phreaks, not computer hackers. |
Eboni Khan
Misanthrope
![]() Join date: 17 Mar 2004
Posts: 2,133
|
07-18-2005 18:19
I'll never understand the hacker mentality. If whoever did this had the technical savvy to pull it off they could have used their skills to do their own cool stuff instead of using it to fuck over other people and destroy their hard work. It's truly amazing how much some people suck. I hope LL is able to find the jackass and smack him down hard. Because hacking is fun. And also, a lot of times sadly, being smart doesnt pay that well. As far as female hackers, I know/knew several ![]() _____________________
|
OSourcerer Flytrap
Registered User
Join date: 23 Jan 2005
Posts: 36
|
07-18-2005 18:22
OK, that's great that LL plugged that hole so quickly. But, what was compromised? Will individuals be notified if their code was released? Will the details of the perpetrator be released to those affected so they can pursue copyright cases as necessary?
_____________________
Copying is not nice.
|
lmho Impfondo
Registered User
Join date: 7 Apr 2005
Posts: 31
|
07-18-2005 18:26
I know most people are angry about this happening, but consider the stealing of scripts a form of very bizarre flattery. Maybe it wasnt an attack (to them) so much as a massive blanket of praise for your hard scripting work. To me, if someone stole MY script I would be happy that they noticed.
|
Francis Chung
This sentence no verb.
![]() Join date: 22 Sep 2003
Posts: 918
|
07-18-2005 18:35
As a security-minded individual and proponent of open-source technologies, many of which form the foundation of SL, I feel I should point out that good security can never be guaranteed through any level of obscurity. ... In short, your code should be secure enough that you can freely allow me to see it, and I'd still be unable to take advantage of that. All forms of authenticated communications that are possible in SL depend on a secret, such as a password. The source code is one such convenient place to embed that password. Being vulnerable to this exploit does not mean that a system was designed for security only through obscurity. I know most people are angry about this happening, but consider the stealing of scripts a form of very bizarre flattery. Maybe it wasnt an attack (to them) so much as a massive blanket of praise for your hard scripting work. To me, if someone stole MY script I would be happy that they noticed. That's funny, I don't feel very flattered. I feel incredibly infuriated. _____________________
--
~If you lived here, you would be home by now~ |
Siggy Romulus
DILLIGAF
![]() Join date: 22 Sep 2003
Posts: 5,711
|
07-18-2005 18:37
I know most people are angry about this happening, but consider the stealing of scripts a form of very bizarre flattery. Maybe it wasnt an attack (to them) so much as a massive blanket of praise for your hard scripting work. To me, if someone stole MY script I would be happy that they noticed. How about if I stole your car? I would only be applauding your excellent taste in vehicles. Praise is when someone says 'Awsome job dude' When someone takes your work without your permission and in most cases uses it in order to profit while putting out minimal effort - thats in no way flattering.. A better analogy would have involved being bent over a barrel without so much as a reach around. No, I consider the theft a theft... Siggy. _____________________
The Second Life forums are living proof as to why it's illegal for people to have sex with farm animals.
I, for one, am highly un-helped by this thread |
blaze Spinnaker
1/2 Serious
Join date: 12 Aug 2004
Posts: 5,898
|
07-18-2005 18:39
All forms of authenticated communications that are possible in SL depend on a secret, such as a password. The source code is one such convenient place to embed that password. Being vulnerable to this exploit does not mean that a system was designed for security only through obscurity. That's not true. The security should depend scraping the LL website. That would be nigh impossible to forge, as someone would have to hack the LL webserver. Checking a source IP address of the incoming email would be good too, but who knows, maybe they might open a relay. The password helps though, but as we have seen, is open to exploits. _____________________
Taken from The last paragraph on pg. 16 of Cory Ondrejka's paper "Changing Realities: User Creation, Communication, and Innovation in Digital Worlds :
"User-created content takes the idea of leveraging player opinions a step further by allowing them to effectively prototype new ideas and features. Developers can then measure which new concepts most improve the products and incorporate them into the game in future patches." |
Alan Palmerstone
Payment Info Used
![]() Join date: 4 Jun 2004
Posts: 659
|
07-18-2005 18:41
OK, that's great that LL plugged that hole so quickly. But, what was compromised? Will individuals be notified if their code was released? Will the details of the perpetrator be released to those affected so they can pursue copyright cases as necessary? Those are good points. While I appreciate that the big commercial engines of SL (major vendors/GOM/Online stores) have been notified, what about us ordinary creators? I have several scripts that are no-mod that I worked very diligently on. I know that the chances of them being taken with this exploit are slim, but I would have liked to have been notified of what the breach was. LL has the ability to identify all creators of objects with no-mod scripts in them. I hope to receive notice at some point now that they have issued the patch. _____________________
Visit Parrot Island - relax on the beach, snuggle at the waterfall, ride the jetskis, make a movie and buy a pool!
|