Private Messages- are they really private?

General discussion - "gossip and tittle tattle"
User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Private Messages- are they really private?

Post by Porty » 10 Nov 2005, 15:52

There has been a flurry of PM's and emails since the locked, now deleted, "Forgive or Revenge" thread.

Some correspondents do not trust the integrity of the PM system and choose to email.

I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.

Are POL private messages really private?

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Re: Private Messages- are they really private?

Post by Dadaist » 10 Nov 2005, 15:57

Porty wrote:There has been a flurry of PM's and emails since the locked, now deleted, "Forgive or Revenge" thread.

Some correspondents do not trust the integrity of the PM system and choose to email.

I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.

Are POL private messages really private?
I didn't know there was a hack. I thought the encryption used on forums was very strong - and assumed that it would be the same for PMs as it was for people's passwords.

That's not to say that the people who run the software could be running a version they made themselves to make copies of PMs, but I doubt it.

In terms of an outsider trying to read them - no chance.

The people who have access to board software - I am unsure.

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 15:59

I hope that I am not getting it wrong about Robin. Someone def did post about php hacks, I think it was that little red breasted deviil but I can't be certain and I cannot recall the thread.

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 16:00

Clever way of getting the title of a deleted thread back on the top of the list though. Foxy's approach was less subtle.

User avatar
wangi
[admin]
Posts: 3442
Joined: 27 May 2004, 10:37
Contact:

Re: Private Messages- are they really private?

Post by wangi » 10 Nov 2005, 16:06

Porty wrote:I suspect this has come about since someone's (Robin?) revelation that hacks exist for php bulletin boards and private messages can be hacked and read. It was further compounded by Bob's on-board implication that himself and Wangi read private messages, which in my view was meant to be a joke.
I missed that comment. Anyway, the answer is yes - I could in fact read your private messages if I so wanted...

... Although not using the forum software as it is (are there hacks? I don't know, and I'd be the who'd have to install them :twisted: ).

The private messages are stored plain text in a table in the database. Myself and xxxx have the technical knowledge and passwords required to do this. I'm pretty sure it goes without saying we don't have the inclination, or the time required!
Last edited by wangi on 10 Nov 2005, 16:15, edited 1 time in total.

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 16:07

Edited: Response to Dada

Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.

BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
Last edited by Porty on 10 Nov 2005, 16:22, edited 1 time in total.

foxy
Posts: 2055
Joined: 05 Nov 2004, 09:04
Location: wherever I lay my hat

Post by foxy » 10 Nov 2005, 16:11

Dadaist wrote:Clever way of getting the title of a deleted thread back on the top of the list though. Foxy's approach was less subtle.
I just went for the "publish and be damned" approach

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 16:15

Thanks Wangi. You answered my previous post before I even posted it.

The comment in question? I read as tongue in cheek and I think you were on honeymoon at the time. Some people are more security conscious/sensitive than I am. (make that almost everyone :wink: )

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 16:26

Porty wrote:Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.

BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
I guess it's just passwords that are stored in an encrypted form - I didn't know PMs were kept on the db as plain text.

Oh well. It's been interesting to see a controversial mod decision from a different angle, although it won't be the last time I manage to stir things up. If I was Bob I would never even have hired me if I'd known that the first thing I was going to do was spill open the RBOS worm can, let alone my unmoderated performace since. Staff, eh.

User avatar
Gemini
Posts: 945
Joined: 05 May 2003, 12:02
Location: Portobello

Post by Gemini » 10 Nov 2005, 17:12

Porty wrote:Edited: Response to Dada

Well it may be clever but it is a coincidence. I assure you it has caused a major flurry, unlike nothing I have witnessed in my long hours here on POL.

BTT: The PM issue obvioulsy bothers people. From what you have said there is no 100% guarantee against a hack or frig.
I saw the first ref. from one mod to another, about reading private messages. :shock:
How can one be certain that hacks/or frig (whatever this means)
mods. dont read pms?

It's a pity, but I don't think I can trust the pm system now.

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 17:24

Gemini wrote:
It's a pity, but I don't think I can trust the pm system now.
Like you trust a lot of systems anyway :roll: :roll: :roll:

User avatar
wangi
[admin]
Posts: 3442
Joined: 27 May 2004, 10:37
Contact:

Post by wangi » 10 Nov 2005, 17:37

Gemini wrote:How can one be certain that hacks/or frig (whatever this means)
mods. dont read pms?
Trust. Plus mods cannot read PMs, and neither can forum administrators. Only those with the username and password to the webserver (myself, xxxx and Bob) and who know the database system (so we remove Bob from the list) can view them.
Gemini wrote:It's a pity, but I don't think I can trust the pm system now.
Do you send your emails plain text, or do you encryt them? If it's plain text (and I'm 99% certain that'll be the case) then you are aware that administrators at every site they pass through between source and destination can read your emails...

User avatar
Bob Jefferson
Posts: 6212
Joined: 11 Dec 2004, 21:16
Location: Planet Porty
Contact:

Post by Bob Jefferson » 10 Nov 2005, 17:53

I think I vaguely remember the post in question. I don't have access to private messages and I have no interest in their content. As regards a mod to facilitate the reading of private messages, I would consider this a gross betrayal of trust and completely unacceptable. I'm sure we all feel the same on this.

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 17:59

wangi wrote:Trust. Plus mods cannot read PMs, and neither can forum administrators. Only those with the username and password to the webserver (myself, xxxx and Bob) and who know the database system (so we remove Bob from the list) can view them....
I do trust the PM system and those of you in charge of it. I recognise that most systems are insecure to a greater or lesser extent.

Unfortunately there are other who don't trust, as usual Gemini is not afraid to go public. Inadvertently, Bob's joshing may have compounded fears, he mentions you as co-conspirator and it seems that he can't read PM's without you or xxxx assistance.

I presume anyone caught abusing PM's would get 86ed?

Is the only way it can be hacked, through yourself and xxxx?

(composed at same time as Bobs post above)

User avatar
Gemini
Posts: 945
Joined: 05 May 2003, 12:02
Location: Portobello

Post by Gemini » 10 Nov 2005, 18:09

Porty wrote:
Gemini wrote:
It's a pity, but I don't think I can trust the pm system now.
Like you trust a lot of systems anyway :roll: :roll: :roll:
Not exactly true!
I certainly dont trust Terrible Tony and his - a ss lickers.
Same goes for G W Bush.
Hackers/frig's/cad's and scoundrels - the latter I am responding to
now :wink:


[/code]

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 18:12

In short - yes. Even if somebody got into the server that hosts the database, they would have to "brute force" the database password. Is that right, wangi?

Or could a hacker simply copy the entire file and dump the contents?

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 18:15

Either way, they would have to be pretty sick and pretty bored.

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 18:17

Porty wrote:Either way, they would have to be pretty sick and pretty bored.
...more likely, pretty immature or wanting money from the company they hacked or kudos from their hacker buddies.

User avatar
Bob Jefferson
Posts: 6212
Joined: 11 Dec 2004, 21:16
Location: Planet Porty
Contact:

Post by Bob Jefferson » 10 Nov 2005, 18:20

So, does anyone have pm correspondence worth hacking? :twisted:

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 18:21

Bob Jefferson wrote:So, does anyone have pm correspondence worth hacking? :twisted:
As far as I know, mine is boring. But let me look.

xxxx
Posts: 332
Joined: 10 Oct 2003, 14:03

Post by xxxx » 10 Nov 2005, 18:23

Gemini,
There's generally 2 reasons for hacking a system:
its easy to do or there's something of value there.
The set up is certainly secure enough to deter the former and I don't think there's much of tradeable value in users' pms.
Short of getting Wangi to build a robot to run things, there has to be humans involved at some point, and you just have to trust them.
Last edited by xxxx on 10 Nov 2005, 18:24, edited 1 time in total.

User avatar
wangi
[admin]
Posts: 3442
Joined: 27 May 2004, 10:37
Contact:

Post by wangi » 10 Nov 2005, 18:23

Dadaist wrote:In short - yes. Even if somebody got into the server that hosts the database, they would have to "brute force" the database password. Is that right, wangi?

Or could a hacker simply copy the entire file and dump the contents?
Yeah, it'll be plain text too in the database table files, so if you can access them (i.e. you're an administrator at textdrive.com) you can read the PMs too.

But those guys don;t even have the time to keep the servers from crashing ;)

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 18:31

wangi wrote:
Dadaist wrote:In short - yes. Even if somebody got into the server that hosts the database, they would have to "brute force" the database password. Is that right, wangi?

Or could a hacker simply copy the entire file and dump the contents?
Yeah, it'll be plain text too in the database table files, so if you can access them (i.e. you're an administrator at textdrive.com) you can read the PMs too.

But those guys don;t even have the time to keep the servers from crashing ;)
Oof. I don't know why I thought that the db file was naturally encrypted and only became the original text when an authenticated query returned.

ecm
Posts: 3053
Joined: 15 Jun 2003, 11:34

Post by ecm » 10 Nov 2005, 19:23

The recent pm flurry could easily have been avoided if some kind of public explanation had been given for the deletion of "that thread".

I still don't see what could have been considered so inflammatory, considering some of the other issues we've discussed along the way. I'm annoyed at the presumption that we couldn't have replied to it in a reasonable fashion.


Anyhoo, as regards privacy of pms, there's not much I would say in a pm that I would be worried about someone else reading.
I think. :?

User avatar
mr magnolia
Posts: 972
Joined: 11 Jul 2004, 22:07
Location: close to the edge
Contact:

Post by mr magnolia » 10 Nov 2005, 19:52

Tell me more about the deleted thread that i haven't seen?

Is it perchance connected with my missing avatar?

Will it return after 90 days?

or perhaps just 28?






:alien:
Every Day Counts

User avatar
Bob Jefferson
Posts: 6212
Joined: 11 Dec 2004, 21:16
Location: Planet Porty
Contact:

Post by Bob Jefferson » 10 Nov 2005, 20:27

Did I fix your avatar, or was that an old one? It was the only one I could find in any case.

User avatar
Jackson Priest
Posts: 493
Joined: 30 Aug 2005, 16:57
Location: Marlborough Street
Contact:

Post by Jackson Priest » 10 Nov 2005, 20:39

er, can someone please tell me what the"Forgive or Revenge" thread was?

Better still, pm me - then we can all read it.

JP.

User avatar
mr magnolia
Posts: 972
Joined: 11 Jul 2004, 22:07
Location: close to the edge
Contact:

Post by mr magnolia » 10 Nov 2005, 21:18

Bob Jefferson wrote:Did I fix your avatar, or was that an old one? It was the only one I could find in any case.
hmm, lovely thanks, Bob.
Every Day Counts

User avatar
Sandra
Posts: 3376
Joined: 17 Nov 2003, 16:50
Location: Portobello

Post by Sandra » 10 Nov 2005, 22:08

Bob Jefferson wrote:So, does anyone have pm correspondence worth hacking? :twisted:
I don't reckon so :lol:

Seeing as we are on the subject of hackers is using your CC card details for online shopping really safe?

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 22:38

Jackson Priest wrote: Better still, pm me - then we can all read it.
JP.
Good one. :D

Jackson Priest wrote: er, can someone please tell me what the"Forgive or Revenge" thread was?
Well at the risk of getting thrown off the forum.....

It was PoP's original thread about his 19 year old son getting beaten up in Newcastle by older boys, it was an attempted robbery. PoP shared his feelings and experience with us and expressed a dilema about revenge or forgiveness. He threw the subject out for discussion. The topic was locked almost immediately (xxxx posted his 2 cents) and then deleted not long after......

Feelings of potentail revenge was perceived as an inappropraite topic for discussion. I am not really clear as to why?

Has to be said that PoP wasn't to bothered but then again he thinks internet debating is a meaningless waste of time
:roll: :roll: :roll: :shock: :shock: :shock:

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 22:40

Sandra wrote:
Seeing as we are on the subject of hackers is using your CC card details for online shopping really safe?
If used with due care and attention, yes it is safe but nothing is 100% safe. There was an item on the news yesterday ; i think it said CC internet fraud was up 60% year on year and Scotland was one of the most fertile areas for the fraudsters.

User avatar
Dadaist
Posts: 6159
Joined: 05 Jul 2004, 19:42
Location: on the fringes of Portobello

Post by Dadaist » 10 Nov 2005, 22:46

Sandra wrote:
Bob Jefferson wrote:So, does anyone have pm correspondence worth hacking? :twisted:
I don't reckon so :lol:

Seeing as we are on the subject of hackers is using your CC card details for online shopping really safe?
If it's with a big established company, or one of the online payment companies like paypal or nochex, I wouldn't worry about it.

Check with your cc company what your protection is from online fraud - they are more worried than you are!

http://www.bbc.co.uk/crime/support/cardfraud.shtml

User avatar
Epykat
Posts: 3915
Joined: 04 Dec 2003, 22:35
Location: Portobello, Edinburgh
Contact:

Post by Epykat » 10 Nov 2005, 22:47

Porty wrote:Either way, they would have to be pretty sick and pretty bored.
And if they weren't either when they started they certainly would be by about half way through :roll: I've no concerns about who reads my pms - they contain the same amount of twaddle that I say in public :lol:
Enough of your nonsense - get back to the Play Pen!

User avatar
Poppy
Posts: 3483
Joined: 08 Feb 2004, 12:02

Post by Poppy » 10 Nov 2005, 22:53

Portly said
he [the highly intelligent PoP] thinks internet debating is a meaningless waste of time
=D> =D> =D> =D> =D> =D>

User avatar
Porty
Posts: 8514
Joined: 08 Jun 2004, 14:30
Location: Organic Market

Post by Porty » 10 Nov 2005, 22:55

It wasn't really him. I made it up. :shock:

Post Reply