|
Author |
Thread Statistics | Show CCP posts - 36 post(s) |

Gnulpie
Minmatar Miner Tech
|
Posted - 2011.04.10 15:44:00 -
[1]
Originally by: CCP Sreegs I'm not claiming. I'm stating outright that customer data was never at risk. We've also said there will be a blog which will detail what occurred and what was wrong.
What do you say about that the "new forums" allowed the injection of any code (depending on the users computer configuration, even keyloggers and other nasty stuff) which would be then executed by the forum users?
Wouldn't you agree that this is not a huge risk of your customers?
You didn't risk your customers data on your internal servers, no. Far WORSE, you risked your customers security as whole.
Do you think it is the right step to downplay this incredible risk?
And what do you say to the rumours that these gaping security holes were all reported in the testing BEFORE the forums went public? Is that true or not? |

Gnulpie
Minmatar Miner Tech
|
Posted - 2011.04.10 16:48:00 -
[2]
At least that CCP Sreegs guy seems to do good work right now.
Props for that. I can imagine way better things to do than talking with angry EVE people on the forums  |

Gnulpie
Minmatar Miner Tech
|
Posted - 2011.04.10 17:18:00 -
[3]
Man, jeez, give them folks at CCP some time to investigate what exactly happend, where the vulnerabilities are, what communication channels failed (if they failed) etc.
This takes time and such things can't be properly done in few hours!
You guys want thorough investigation and at the same time you want results, blogs and whatnot already yesterday. That's not working!
If there is still no public reply in a few days, THEN is the time to make a huge uproar, but for now let them do their work.
Ranting, venting anger and frustration is good and fine, but after that, let it go and calm down. |

Gnulpie
Minmatar Miner Tech
|
Posted - 2011.04.11 14:03:00 -
[4]
Edited by: Gnulpie on 11/04/2011 14:03:23
Originally by: Zey Nadar
Pointing out that there are more glaring holes in the new forum than just the signature exploit.
And the best part is that these holes were reported in the test phase. 
Do you have any proof that those issues were reported? Any mails/correspondence? Forum posts? Bug ID's?
And who reported them? And in which detail were those problems reported? |
|
|
|