Go Back   vb.org Archive > Community Central > vBulletin.org Site Feedback
FAQ Community Calendar Today's Posts Search

Closed Thread
 
Thread Tools Display Modes
  #31  
Old 06-27-2005, 03:03 PM
Chris M's Avatar
Chris M Chris M is offline
 
Join Date: Dec 2001
Location: Northampton, England
Posts: 6,186
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Xenon
As already said, it's because of privacy issues.

A user who posts within the supportthread, realises, that when a security flaw is found, he could be a possible victim, but if he does not post then he has to be sure he is "safe".
Of course we could just generate a list just for authors, but there could always be a black sheep there as well.

I can understand both sides, i sometimes miss that feature myself, but as said, the disadvantages are bigger than the fun factor, so we won't add it again.
If it is just for authors, how could there be a black sheep?

I fail to see how showing who installed the hack to the author will cause problems...

Satan
  #32  
Old 06-27-2005, 03:04 PM
Dan's Avatar
Dan Dan is offline
 
Join Date: Dec 2002
Location: Titusville, Florida
Posts: 1,787
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by hellsatan
If it is just for authors, how could there be a black sheep?

I fail to see how showing who installed the hack to the author will cause problems...

Satan
The very highly unlikely possibility that author is the one who coded the vulnerability and WANTS to take advantage of it maybe?

Just my two pence.
  #33  
Old 06-27-2005, 03:14 PM
Chris M's Avatar
Chris M Chris M is offline
 
Join Date: Dec 2001
Location: Northampton, England
Posts: 6,186
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

In which case it won't matter if he can see the list or not, as users such as myself or others will pick up on the coded vulnerability, report it, and it will be closed - Or an investigation will be done and the author banned

Satan
  #34  
Old 06-27-2005, 03:20 PM
Xenon's Avatar
Xenon Xenon is offline
 
Join Date: Oct 2001
Location: Bavaria
Posts: 12,878
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

well, there is still a possibility, and we don't need it.
  #35  
Old 06-27-2005, 04:02 PM
Paul M's Avatar
Paul M Paul M is offline
 
Join Date: Sep 2004
Location: Nottingham, UK
Posts: 23,748
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

This is just plain paranoia - if a hack author wanted to do this then he would search google for boards with his hack - far easier than hunting for usernames here - which in most cases cannot be tracked back to an actual board anyway.

If you can't be bothered to do it, just say so, but please don't use lame excuses .
  #36  
Old 06-27-2005, 04:22 PM
tamarian tamarian is offline
 
Join Date: Oct 2001
Location: Canada
Posts: 1,205
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by MarcoH64
From a privacy point of view this is undesirable. What is information a coder "needs"?
I disagree.

Many don't click install anyway.

If someone really has privacy issues, they still have the option to:

1. Not show their URL in their profile
2. Or, not click install, like many others who don't click install for any reason.

This feature should be returned, IMHO.

No only for hack authors, but other members should be able to see who installed this hack. It has some benefits:

1. See the hack in action in various environemnts, setups
2. If they have support issues the author can't figure, they can check with others who have it installed and working in similar evironemnt

It would be a shame to hide such information, just because a few people want to click install, but don't want anyone to know. Especially since they have the option not to click. (My guess is that they would not click anyway).

The explot reason is bogus, IMHO. Peope who hunt explots use scripts to scan forums, regardless of who clicked what. vBulletin itself had explots, and it could be found from Google, or from vB's forum signatures and profiles. This only gives a false sense of security. And if someone is really paranoid about it, they have the option not to click install.
  #37  
Old 06-27-2005, 04:34 PM
Colin F's Avatar
Colin F Colin F is offline
 
Join Date: Jul 2004
Location: Switzerland
Posts: 1,551
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Showing who installed for all users will most likely never happen.

The reasoning that users can just not click on install isn't really valid, as the install button has benefits for the user clicking, in that he'll be notified if an exploit is found or there are big updates.
  #38  
Old 06-27-2005, 04:46 PM
tamarian tamarian is offline
 
Join Date: Oct 2001
Location: Canada
Posts: 1,205
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Colin F
Showing who installed for all users will most likely never happen.

The reasoning that users can just not click on install isn't really valid, as the install button has benefits for the user clicking, in that he'll be notified if an exploit is found or there are big updates.
They can subscribe to the thread.

It think this is being overly protective, especially since it doesn't offer any protection. Just limits a great feature.
  #39  
Old 06-27-2005, 04:59 PM
Colin F's Avatar
Colin F Colin F is offline
 
Join Date: Jul 2004
Location: Switzerland
Posts: 1,551
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by tamarian
They can subscribe to the thread.

It think this is being overly protective, especially since it doesn't offer any protection. Just limits a great feature.
That's not comparable.

Subscribing to the thread notifies you with all the answers in the thread. Popular modifications can have over 1000 posts in the thread.
That's not the same as recieving one update when a security vulnerability shows up.
  #40  
Old 06-27-2005, 05:08 PM
tamarian tamarian is offline
 
Join Date: Oct 2001
Location: Canada
Posts: 1,205
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Colin F
That's not comparable.

Subscribing to the thread notifies you with all the answers in the thread. Popular modifications can have over 1000 posts in the thread.
That's not the same as recieving one update when a security vulnerability shows up.
This is vbulletin.org, which is hacked to death. It's trivial to add a "send security update", that is merely a special case of notification.

You can just say "we don't want to do it or put it back", and it would be your prerogative. But the reasons given are too weak, IMHO, considering that they are no protection, and can be address if necessary by trivial changes.
Closed Thread


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT. The time now is 12:58 PM.


Powered by vBulletin® Version 3.8.12 by vBS
Copyright ©2000 - 2024, vBulletin Solutions Inc.
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.05672 seconds
  • Memory Usage 2,257KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (1)ad_showthread_beforeqr
  • (1)ad_showthread_firstpost
  • (1)ad_showthread_firstpost_sig
  • (1)ad_showthread_firstpost_start
  • (6)bbcode_quote
  • (1)footer
  • (1)forumjump
  • (1)forumrules
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (1)navbar
  • (3)navbar_link
  • (120)option
  • (1)pagenav
  • (1)pagenav_curpage
  • (4)pagenav_pagelink
  • (10)post_thanks_box
  • (10)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (10)post_thanks_postbit_info
  • (10)postbit
  • (10)postbit_onlinestatus
  • (10)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open
  • (1)tagbit_wrapper 

Phrase Groups Available:
  • global
  • inlinemod
  • postbit
  • posting
  • reputationlevel
  • showthread
Included Files:
  • ./showthread.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showthread_start
  • showthread_getinfo
  • forumjump
  • showthread_post_start
  • showthread_query_postids
  • showthread_query
  • bbcode_fetch_tags
  • bbcode_create
  • showthread_postbit_create
  • postbit_factory
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • pagenav_page
  • pagenav_complete
  • tag_fetchbit_complete
  • forumrules
  • navbits
  • navbits_complete
  • showthread_complete