Private Messages- are they really private?
Private Messages- are they really private?
There has been a flurry of PM's and emails since the locked, now deleted, "Forgive or Revenge" thread.
Some correspondents do not trust the integrity of the PM system and choose to email.
I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.
Are POL private messages really private?
Some correspondents do not trust the integrity of the PM system and choose to email.
I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.
Are POL private messages really private?
Re: Private Messages- are they really private?
I didn't know there was a hack. I thought the encryption used on forums was very strong - and assumed that it would be the same for PMs as it was for people's passwords.Porty wrote:There has been a flurry of PM's and emails since the locked, now deleted, "Forgive or Revenge" thread.
Some correspondents do not trust the integrity of the PM system and choose to email.
I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.
Are POL private messages really private?
That's not to say that the people who run the software could be running a version they made themselves to make copies of PMs, but I doubt it.
In terms of an outsider trying to read them - no chance.
The people who have access to board software - I am unsure.
Re: Private Messages- are they really private?
I missed that comment. Anyway, the answer is yes - I could in fact read your private messages if I so wanted...Porty wrote:I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.
... Although not using the forum software as it is (are there hacks? I don't know, and I'd be the who'd have to install them
The private messages are stored plain text in a table in the database. Myself and xxxx have the technical knowledge and passwords required to do this. I'm pretty sure it goes without saying we don't have the inclination, or the time required!
Last edited by wangi on 10 Nov 2005, 16:15, edited 1 time in total.
Edited: Response to Dada
Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.
BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.
BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
Last edited by Porty on 10 Nov 2005, 16:22, edited 1 time in total.
I guess it's just passwords that are stored in an encrypted form - I didn't know PMs were kept on the db as plain text.Porty wrote:Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.
BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
Oh well. It's been interesting to see a controversial mod decision from a different angle, although it won't be the last time I manage to stir things up. If I was Bob I would never even have hired me if I'd known that the first thing I was going to do was spill open the RBOS worm can, let alone my unmoderated performace since. Staff, eh.
I saw the first ref. from one mod to another, about reading private messages.Porty wrote:Edited: Response to Dada
Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.
BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
How can one be certain that hacks/or frig (whatever this means)
mods. dont read pms?
It's a pity, but I don't think I can trust the pm system now.
Trust. Plus mods cannot read PMs, and neither can forum administrators. Only those with the username and password to the webserver (myself, xxxx and Bob) and who know the database system (so we remove Bob from the list) can view them.Gemini wrote:How can one be certain that hacks/or frig (whatever this means)
mods. dont read pms?
Do you send your emails plain text, or do you encryt them? If it's plain text (and I'm 99% certain that'll be the case) then you are aware that administrators at every site they pass through between source and destination can read your emails...Gemini wrote:It's a pity, but I don't think I can trust the pm system now.
- Bob Jefferson
- Posts: 6212
- Joined: 11 Dec 2004, 21:16
- Location: Planet Porty
- Contact:
I think I vaguely remember the post in question. I don't have access to private messages and I have no interest in their content. As regards a mod to facilitate the reading of private messages, I would consider this a gross betrayal of trust and completely unacceptable. I'm sure we all feel the same on this.
I do trust the PM system and those of you in charge of it. I recognise that most systems are insecure to a greater or lesser extent.wangi wrote:Trust. Plus mods cannot read PMs, and neither can forum administrators. Only those with the username and password to the webserver (myself, xxxx and Bob) and who know the database system (so we remove Bob from the list) can view them....
Unfortunately there are other who don't trust, as usual Gemini is not afraid to go public. Inadvertently, Bob's joshing may have compounded fears, he mentions you as co-conspirator and it seems that he can't read PM's without you or xxxx assistance.
I presume anyone caught abusing PM's would get 86ed?
Is the only way it can be hacked, through yourself and xxxx?
(composed at same time as Bobs post above)
Not exactly true!Porty wrote:Like you trust a lot of systems anywayGemini wrote:
It's a pity, but I don't think I can trust the pm system now.![]()
![]()
I certainly dont trust Terrible Tony and his - a ss lickers.
Same goes for G W Bush.
Hackers/frig's/cad's and scoundrels - the latter I am responding to
now
[/code]
- Bob Jefferson
- Posts: 6212
- Joined: 11 Dec 2004, 21:16
- Location: Planet Porty
- Contact:
Gemini,
There's generally 2 reasons for hacking a system:
its easy to do or there's something of value there.
The set up is certainly secure enough to deter the former and I don't think there's much of tradeable value in users' pms.
Short of getting Wangi to build a robot to run things, there has to be humans involved at some point, and you just have to trust them.
There's generally 2 reasons for hacking a system:
its easy to do or there's something of value there.
The set up is certainly secure enough to deter the former and I don't think there's much of tradeable value in users' pms.
Short of getting Wangi to build a robot to run things, there has to be humans involved at some point, and you just have to trust them.
Last edited by xxxx on 10 Nov 2005, 18:24, edited 1 time in total.
Yeah, it'll be plain text too in the database table files, so if you can access them (i.e. you're an administrator at textdrive.com) you can read the PMs too.Dadaist wrote:In short - yes. Even if somebody got into the server that hosts the database, they would have to "brute force" the database password. Is that right, wangi?
Or could a hacker simply copy the entire file and dump the contents?
But those guys don;t even have the time to keep the servers from crashing
Oof. I don't know why I thought that the db file was naturally encrypted and only became the original text when an authenticated query returned.wangi wrote:Yeah, it'll be plain text too in the database table files, so if you can access them (i.e. you're an administrator at textdrive.com) you can read the PMs too.Dadaist wrote:In short - yes. Even if somebody got into the server that hosts the database, they would have to "brute force" the database password. Is that right, wangi?
Or could a hacker simply copy the entire file and dump the contents?
But those guys don;t even have the time to keep the servers from crashing
The recent pm flurry could easily have been avoided if some kind of public explanation had been given for the deletion of "that thread".
I still don't see what could have been considered so inflammatory, considering some of the other issues we've discussed along the way. I'm annoyed at the presumption that we couldn't have replied to it in a reasonable fashion.
Anyhoo, as regards privacy of pms, there's not much I would say in a pm that I would be worried about someone else reading.
I think.
I still don't see what could have been considered so inflammatory, considering some of the other issues we've discussed along the way. I'm annoyed at the presumption that we couldn't have replied to it in a reasonable fashion.
Anyhoo, as regards privacy of pms, there's not much I would say in a pm that I would be worried about someone else reading.
I think.
- mr magnolia
- Posts: 972
- Joined: 11 Jul 2004, 22:07
- Location: close to the edge
- Contact:
- Bob Jefferson
- Posts: 6212
- Joined: 11 Dec 2004, 21:16
- Location: Planet Porty
- Contact:
- Jackson Priest
- Posts: 493
- Joined: 30 Aug 2005, 16:57
- Location: Marlborough Street
- Contact:
- mr magnolia
- Posts: 972
- Joined: 11 Jul 2004, 22:07
- Location: close to the edge
- Contact:
Good one.Jackson Priest wrote: Better still, pm me - then we can all read it.
JP.
Well at the risk of getting thrown off the forum.....Jackson Priest wrote: er, can someone please tell me what the"Forgive or Revenge" thread was?
It was PoP's original thread about his 19 year old son getting beaten up in Newcastle by older boys, it was an attempted robbery. PoP shared his feelings and experience with us and expressed a dilema about revenge or forgiveness. He threw the subject out for discussion. The topic was locked almost immediately (xxxx posted his 2 cents) and then deleted not long after......
Feelings of potentail revenge was perceived as an inappropraite topic for discussion. I am not really clear as to why?
Has to be said that PoP wasn't to bothered but then again he thinks internet debating is a meaningless waste of time
If used with due care and attention, yes it is safe but nothing is 100% safe. There was an item on the news yesterday ; i think it said CC internet fraud was up 60% year on year and Scotland was one of the most fertile areas for the fraudsters.Sandra wrote:
Seeing as we are on the subject of hackers is using your CC card details for online shopping really safe?
If it's with a big established company, or one of the online payment companies like paypal or nochex, I wouldn't worry about it.Sandra wrote:I don't reckon soBob Jefferson wrote:So, does anyone have pm correspondence worth hacking?
Seeing as we are on the subject of hackers is using your CC card details for online shopping really safe?
Check with your cc company what your protection is from online fraud - they are more worried than you are!
http://www.bbc.co.uk/crime/support/cardfraud.shtml
And if they weren't either when they started they certainly would be by about half way throughPorty wrote:Either way, they would have to be pretty sick and pretty bored.
Enough of your nonsense - get back to the Play Pen!