Welcome to the Second Life Forums Archive

These forums are CLOSED. Please visit the new forums HERE

Request for Exploit handling procedure

Aodhan McDunnough
Gearhead
Join date: 29 Mar 2006
Posts: 1,518
07-28-2006 22:59
Dear Lindens,

Apologies in advance if this is a bit long, but I hope something constructive can be done.

The recent suspensions of Cristiano Midnight and Cilis Nephilim have caused quite a bit of friction in the community. It is friction the residents and Linden Lab can do without.

Some accuse the moderators of not being even-handed. Some question the policy. But for me, those are not the questions to ask.

I’m looking to the future. I fully understand Linden Lab’s need for confidentiality of data regarding exploits and suspensions. I fully understand the gravity of exploits. I also understand the needs of the community with regard to the issue of exploits.

We don’t need any changes in policy. We only need a means of prevention. We can keep such ugly incidents from repeating.

1. Linden Lab needs that exploits not be disclosed. This is for damage control purposes obviously since the less people know how to perform an exploit, the less damage results.

2. The community needs to know that there’s a problem and how to protect themselves from such problems. This is also for damage control purposes. This aspect is not needed in typical MMOGs because there's no true user content to damage. But in SL, residents do have things they can lose.

What the community needs is a procedure or protocol to follow in the event of exploit discovery such that the above two needs are addressed.

Cristiano sent those warnings most likely because he had no idea if the exploit was already being handled or not. Since he felt unsure it was being handled, he took it upon himself to warn the community.

What I believe we need is improved feedback regarding status.

My suggestion is:
  1. The resident who has completed investigation of an exploit reports the exploit to Linden Lab using the bug report tool and places "EXPLOIT" in the title. (This procedure is a given, and is as stated by Brent Linden).
  2. The SL bug report system sends an automated message upon receipt. (Suggested add) What will be good after this is if a second message , sent manually by email and in-world IM, confirms when an investigator is actually looking into it. At least the reporting resident will know that the exploit is being handled already.
  3. At this point the reporting resident can rest.
  4. One hour or less after the manual message is sent a forum post is made by LL regarding the status. In the event that the investigation is not complete the announcement, without disclosing the exploit being investigated, should include preventive and protective measures residents should take.
The two critical elements here are the manual feedback, and the timeliness of the status announcement.

So what answer am I seeking? Either.
  1. Is this protocol workable? or
  2. Is there an even better protocol that we can follow?
It would help greatly if residents had an explicit step-by-step protocol that could be followed that would satisfy both Lindens’ need for confidentiality and the residents’ need for protection and enough feedback so that people will know things are safely in the hands of Linden Lab.

This way we avoid all future CrisMid cases.

_____________________
Aodhan's Forge shop at slurl.com/secondlife/Rieul/95/213/107
Torley Linden
Enlightenment!
Join date: 15 Sep 2004
Posts: 16,530
07-31-2006 10:30
We're definitely making aggressive (in a receptive, friendly way) steps towards something similar to what you suggest. So in agreement, I think you'll find it to be quite proactive.

Specifically, we're hoping to have a special EXPLOIT category to report bugs to, and that it should only be used in case of emergency. And yes, ideally, it'll provide a priority line to better connect the reporter with the Lindens in the know, so such problems can be checked out and action gets taken ASAP. And since awareness comes sooner, a forum announcement and other news channelling can be done *much* faster. This would bypass noise and confusion.

In short, cuts down on the crap and gets to the point.
_____________________