View Single Post
  #15  
Old 09-11-2009, 08:35 AM
Marco van Herwaarden Marco van Herwaarden is offline
 
Join Date: Jul 2004
Posts: 25,415
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Ok let me start by addressing some of the issues you raise in this thread.

There are only 2 situations in which a modification is quarantined:

- A (possible) exploit has been discovered. As per our Mod Exploit Guidelines we will snet out a warning email to all that have marked the modification as installed. Such an email is only sent in case of an exploit. So if you receive such an email it is to warn you about a possible vulnerability.
- The modification is breaking a rule that can be resolved. No email to the users is sent in this case as this is a private issue between vB.org (rules) and the author.

Details of a possible vulnerability are only sent to the coder and not to the users. We have no intention to change this. But if you think that we should update our text to make it more clear that the email was sent because of a possible vulnerability, then feel free to suggest an alternative text. But the current text was made after discussions with members.

Files are not available for download when a modification is quarantined. One of the reasons for this is not to help potential hackers to exploit such a vulnerability before a fix is provided by the author. But also the current version might not be available anymore.

Files can become unavailable for many reasons, in most of the situations these files are either deleted or can not be shared anymore for copyright issues. This is not limited to a quarantined modification. For this reason it is always your own responsibility to ensure that you can uninstall a modifiction, even if the files are not available anymore. There are many ways to solve this, most people simply save a copy of a modification when they install it. You can try to make this our responsibility, but how you run your board is really your own.

Now let's address your complaint on how you are treated by staff.

- You start a thread on a topic that has already been discussed before, and you know this. Now i don't have a problem with someone making a suggestion again, but you bring no new arguments, you only repeat the same as in older threads on this topic. Not a surprise that you will receive the same answers.
- The title of your post is not like your intentions are to make a serious suggestion, it is more the start of a rant: Concerned about another quarantine email I received. Does vB.org just not give a damn. If it had been only the first sentence it would have been fine, but by adding that vb.org doesn't give a damn you are already paving the way to get a negative response by staff.
- "Why the HELL are the people who have marked the modification as installed not given the reason for the quarantine?" Why the need to use langauge like "Why the HELL". Also you are asking a question that has been answered to before.
- "And it's my assumption that vB.org just does not give a damn about its Members' board security if the only thing to do is send that bogus email as quoted above." Again, no positive suggestions, only a rant. If you think these mails are bogus then this would invalidate most of your rant. If you don't want them, don't mark modifications as installed. Sending out a warning is a service we provide to our members to help them mitigate security issues.

How do you think staff should respond when you only post a rant about things already discussed before in such a negative way?

I won't go anyalyzing your other posts in this thread as i think i already gave enough examples from your first post in this thread, but your responses only go further down the road.
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01140 seconds
  • Memory Usage 1,772KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete