| Author |
Thread Statistics | Show CCP posts - 12 post(s) |
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 13:17:00 -
[1] - Quote
We had some security concerns with allowing the embedding of external images. ItGÇÖs something weGÇÖll be enabling in the future but it was dropped from this release in the interest of doing it properly/safely. This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 13:39:00 -
[2] - Quote
What Aethlyn wrote above is essentially correct. A few browsers also have problems with https:// sites linking to non-https images or images on a different domain. This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 13:51:00 -
[3] - Quote
Jade Constantine wrote:CCP Karuck wrote:What Aethlyn wrote above is essentially correct. A few browsers also have problems with https:// sites linking to non-https images or images on a different domain. So how are you going to resolve this problem to allow the posting of image links CCP Karuck? Do you have a gameplan going forwards over the next few days to resolve the issue? How do other modern forums resolve these concerns for example?
Image links are a completely different thing, and you do get a warning when clicking any links. At least links can't be a script marauding as an image exploiting a security hole in your browser.
Most public forums don't use https, and are wide open to packet sniffers. Since the forums, EVE Gate and other upcomings webs here use your actual EVE login we are taking steps to secure your information more (yes you can joke all you want about this, but we are).
I'm sorry but I don't have a timeline for when this will be ready, that question would have to be answered by the forum producer. This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 14:04:00 -
[4] - Quote
Riflin' Betty wrote:CCP Karuck wrote:
Image links are a completely different thing, and you do get a warning when clicking any links. At least links can't be a script marauding as an image exploiting a security hole in your browser.
By this exact logic you are now saying that remote scripting exploits WERE possible on the previous iteration of this forum, despite your exact claims that the opposite was true. Please resolve this logical fallacy for me?
If you are referring to the short period where we did allow signatures on the first (failed) attempt at launching these forums then yes, it was a possibility. But it is a pretty remote possibilty, and this possibility exists on pretty much all public forums that do allow external image linking. I'd like to underline that this is a remote possibility, and (known) flaws like these have been fixed in all modern browsers.
But like I stated in my previous reply this isn't the only concern. Some browsers give you a warning if you try to request non-https images from a https website (for a good reason too).
Privacy is a concern too. Example: By hosting an image on my own webserver and putting it in my signature on forums, I can get a pretty good picture of the usage of that forum and where people using it are from.. as well as log IP addresses etc. I don't want to scare people, but do you want RMT tracking your IPs? This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 14:05:00 -
[5] - Quote
Jade Constantine wrote:My apologies for the confusion of terminology. I meant embedded images of course. I'm not that keen on the warning message for external links myself - quite immersion-breaking.
Please correct me if I'm wrong, but as far as I know you cannot embed images in your posts either.
Jade Constantine wrote:CCP Karuck wrote: Most public forums don't use https, and are wide open to packet sniffers. Since the forums, EVE Gate and other upcomings webs here use your actual EVE login we are taking steps to secure your information more (yes you can joke all you want about this, but we are). Okay that makes sense certainly. Have you considered the alternative I mentioned above about hosting a ccp-controlled image upload service for signatures and in-character imagery and allowing people to embed directly from the ccp secure webserver?
Yes, that is one of the options being considered. This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 14:14:00 -
[6] - Quote
Riflin' Betty wrote: Then why did the DevBlog say it wasn't possible?
Further you didn't allow anything, you left open some awful holes that made it possible to do despite your intent not to.
Short reply: Two different things, no exploits got out.
Please link me to the reference you are talking about, but I'm pretty sure they were talking about embedding scripts in the signature, which is a completely different type of exploit. If you have a pretty modern browser (not 4-5+ years old) then the case I am talking about is not possible anymore, at least no known exploits. The case we discussed in the devblog is possible in all browsers but would have been a programming fail on our end. In that case the browser simply can't tell the difference between a normal script and a malicious one.
This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 14:25:00 -
[7] - Quote
Riflin' Betty wrote: if you're not allowing images now for some nebulous fear of 'sploits, then by your definition exploits were possible when you released the half-behinded version of this forum before.
Then by your definition you can call pretty much every forum out there that allows external images "half baked" as well. Also, read my other replies.. this "remote change in hell" exploit was not the only reason we turned this off.
No one is perfect, it's the will to make things better that matters more to me.
This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 14:38:00 -
[8] - Quote
Riflin' Betty wrote: Exactly. So why are the pictures off if it's apparently ok for every other forum on earth?
The Internet is far from being a perfect place. Most people thought non-https was ok until people started hacking their Facebook accounts with Firesheep.
This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 14:53:00 -
[9] - Quote
Riflin' Betty wrote: There is no compelling argument for you to disallow the image tag other than the fact that one of your webgurus decided it was not esthetically pleasing.
How about you read the other reasons I posted and stop trolling me? Yes it is true we had some embarrassing exploits in the old forums, but we are working on improving things. If you really are so interested in web security, then how about you take a serious look at other websites you use on a daily basis? It's a scary world out there..
This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 15:01:00 -
[10] - Quote
Jade Constantine wrote: I can imagine the meetings about having approval meetings for the planning meetings that get delayed pending approval of the planning approval process taking quite a while...
Actually, we're just waiting for a new TPS Cover Report ;) This signature has no images |
|
|

CCP Karuck
C C P C C P Alliance
12

|
Posted - 2011.09.06 15:06:00 -
[11] - Quote
Riflin' Betty wrote: I do believe I still have the right to disagree?
Of course you do, and we do value constructive feedback. But apparently you haven't read our other reasons for doing this (or you are simply trolling). Even I myself have downplayed the remote chance of getting an injection attack via an img tag.
I'm sorry I'm not going to reply further on this, but will continue monitoring other feedback. This signature has no images |
|
| |
|