Draco
2bOrNot2b
- Joined
- Mar 30, 2001
- Posts
- 6,762
Never said:I’m not holier, though I’d say I’m superior.
UH-HUH, if you say so, thats your opinion and you're most welcome to it.
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Never said:I’m not holier, though I’d say I’m superior.
Lancecastor said:You're still right, Draco.
Despite Their childish "You're either with Laurel or against her" heirarchical closed-shop nonsense, you're still right.
Thanks for raising it.
Lance
Never said:You’re telling me something you’ve already said. I know what you think it insecure. I want to know why or how it’s insecure.
Draco, I have to go along with Never and others; I still don't see this as a security problem. To me, the issues of being able to log on multiple times and the hypothetical ability of people being able to hack into your account are two different and separate issues.Draco said:Thats the whole CRUX of it...if others are using security settings...why aren't they in use here. Specially after all the bullshit a few weeks ago about SO & SO's account getting hacked and PM"s being emailled here, there and everywhere?
AND THAT FOLKS IS MY FINAL WORD ON THIS MATTER.
AMEN.
Not afraid of controversy, but telling me if I disagree I shouldn't reply? I believe you said, "...if you dont like the thread content, dont reply..."Draco said:Not a problem Lance, just doing my bit. I've never been afraid of a bit of controversy, and I'm not knocking the LIT board in any way shape or form, and not knocking Laurel or Manu either, they both do a fine job in running the place. It was just something I discovered totally by accident and wondered if others had too. I didn't know that I would be sticking my head "into the lions den" with this one.
Draco said:I tried this on another V-Bulletin site where I am a member. I logged in on my desktop machine, then fired up my laptop, dialed up and tried to log into my account ...it BLOCKED it.
Funny thing is, it is the EXACT same version of V-Bulletin
Now, if they can employ a simple security measure like "detecting and blocking" a secong log-in attempt, surely it can be employed here.
Thats the whole CRUX of it...if others are using security settings...why aren't they in use here.
yes, but this one goes to 11Lancecastor said:Ahhhh....I think you've touched upon the crux of the matter indeed.
Multiple log-ins would also enable House Trolls & Fluffers to increase posts and steer discussions, particulary in the absence of Unregistered as an option.
Why else would it be left on? I'm open to suggestion, as always.
Lance
JerseyBoy said:yes, but this one goes to 11
Lit automatically logs you out after you've been inactive for about 20mins or so (I don't know exactly, but seems around that), that's why your 'on-line' indicator in your posts doesn't stay highlighted even when you've set your account to auto-login. So, assuming you hadn't accessed your account from grandma's for at least that long, you'd be able to access it from your house.JerseyBoy said:so...if you log into Lit at grandma's house and forget to log out you'll never be able to log back in again until you make that 12 hour drive again next thanksgiving?
course you could call grandma and have her log you out...
Each and every site could allow multiple accounts to be logged in at the same time. Pay sites will track this to check for password sharing.
Like Never said I just don't see how this is unsecure...
Draco said:The ONLY reason I used the references to ICQ Yahoo etc is...they use password protection, and if you try to log in from a second machine, they detect the log-in attempt and block it. I didn't want a discussion on what protocols each one uses, what their respective CEO's had for breakfast or whatever. I was simply quoting them as examples.
crysede said:Lit automatically logs you out after you've been inactive for about 20mins or so (I don't know exactly, but seems around that), that's why your 'on-line' indicator in your posts doesn't stay highlighted even when you've set your account to auto-login. So, assuming you hadn't accessed your account from grandma's for at least that long, you'd be able to access it from your house.
True. It also makes it difficult to lock someone out of their account if you do have their password.The Heretic said:This isn't a security hole since it doesn't get you someone's password if you don't already have it, and it doesn't make it any easier to hack their password or their PMs or any other confidential info - it just makes it easier to throw temper tantrums.
Well, ya gotta admit that for a company that uses underhanded means to wreck its competitors, with all their billions of dollars in resources, to have on the market as an even remotely viable alternative a system written by college geeks with too much spare time on their hands is pretty damn funny.On a different subject; as for the security holes in MS products vs. Linux etc. - there have been more security alerts for Linux products than for MS products, bother by the vendors themselves and by independent sources such as CERT. The MS holes make the news because it is so popular and MS is the company that people love to hate. I am not defending them; even though they are virtually my neighbors, I don't like many of their business practices either - but the reason most people don't like them is that they are popular, they are successful and they do make good software - in essence they are jealous even if they won't admit it.
But then, if someone had your password, they could log in while you were logged out, and prevent you from logging in again. How would that enhance your security?Draco said:Now, if they can employ a simple security measure like "detecting and blocking" a secong log-in attempt, surely it can be employed here.
It is down right hilarious.Byron In Exile said:True. It also makes it difficult to lock someone out of their account if you do have their password.Well, ya gotta admit that for a company that uses underhanded means to wreck its competitors, with all their billions of dollars in resources, to have on the market as an even remotely viable alternative a system written by college geeks with too much spare time on their hands is pretty damn funny.
Most of what you talk about is server side stuff - an area where MS is woefully behind in almost all respects, including security. OTOH, they are the leader on the desktop - but slowly loosing market share (but not their technology lead) there.As for security, I've seen several Microsoft-based systems compromised or infected, but never a unix system, and I've used unix more. And all the viral trash you see in server logs comes from infected Microsoft-based systems. They're more popular, and therefore more of a target, but still it appears that the security problems they do have, while fewer, are more severe. With their resources, it seems one should expect better.
I don't know if I'd call it good software. The words "bloated" and "buggy" come to mind, although I understand they've cleaned up their act a lot. (I recently had to shut down a unix web server that had been running with 1116 days' uptime. That's stability. Try running a Windows-based server for three years straight without a reboot!) But Microsoft still seem to be fixated on this idea of violating industry standards in order to force the use of their software. They have been and are very successful, but I'm not jealous. I just think they're evil. [/B]
I'm never automatically logged out regardless of how long I've been inactive. If I forget to log out, the next day I'll still be logged in. It could be a function of something local like browser settings, I suppose.crysede said:Lit automatically logs you out after you've been inactive for about 20mins or so (I don't know exactly, but seems around that), that's why your 'on-line' indicator in your posts doesn't stay highlighted even when you've set your account to auto-login. So, assuming you hadn't accessed your account from grandma's for at least that long, you'd be able to access it from your house.
Microsoft isn't evil, they just make really crappy operating systems. - Linus TorvaldsThe Heretic said:I don't think they are evil, although they sometimes do bad things to maintain their predominance. I liken them more to a cult, and believe me, it is a very apt analogy. I know a lot of people who have worked there and who still work there, and I am very familiar with how they indoctrinate their people and why they hire the people they do.
Are you sure you aren't simply being automatically logged back in when you contact the Lit server?Byron In Exile said:I'm never automatically logged out regardless of how long I've been inactive. If I forget to log out, the next day I'll still be logged in. It could be a function of something local like browser settings, I suppose.
I checked and that option is set to Yes, so apparently I am being logged out and in again transparently.crysede said:Are you sure you aren't simply being automatically logged back in when you contact the Lit server?
If you have the 'Automatically login when you return to the site' option selected, then that's what's happening.
Yup - that would definitely be possible: if multiple login's were not allowed, then the hijacker could keep you out of your account as long as they did something every 20 min's or so. (Of course, the moment they accessed your account they could just change the password to keep you out permanently.)Byron In Exile said:I checked and that option is set to Yes, so apparently I am being logged out and in again transparently.
But that means it would indeed be possible, if a user were inactive long enough, and multiple logins were disabled, to hijack their account, provided one knew the password, and to keep the account active to prevent their logging back in. (At least until they sent Lit an email... lol)
Draco said:
WE ARE NOT SECURE.
We're secure from trolly-yahoos with cyber delusions of grandeur - but someone who actually knew what they were doing wouldn't have a problem hijacking your account on Lit. Of course this still wouldn't tell them where you lived, or give them any other valuable information about you, or allow them actually affect your life in anyway whatsoever...Dixon Carter Lee said:In the three years I've been here I've had every trolly-yahoo with cyber delusions of grandeur from XxplorHer to Hanns Schmidt, every would be nemesis Literotica's EVER had, tell me they're going to apply their astounding hacking skills to find me and stuff me in their girly gym locker, and you know what? They haven't.
WE ARE SECURE.
They own the desktop, but I still miss OS/2.The Heretic said:It is down right hilarious.
Most of what you talk about is server side stuff - an area where MS is woefully behind in almost all respects, including security. OTOH, they are the leader on the desktop - but slowly loosing market share (but not their technology lead) there.
I know exactly what you mean, and it's a good analogy. I have a friend I knew in high school that eventually went to work for them. Since then, we don't speak much anymore. It wasn't conciously anything to do with that, he just... sort of... "changed."I don't think they are evil, although they sometimes do bad things to maintain their predominance. I liken them more to a cult, and believe me, it is a very apt analogy. I know a lot of people who have worked there and who still work there, and I am very familiar with how they indoctrinate their people and why they hire the people they do.
I agree -- for lo, the time shall come when their great temples are converted into low-cost housing, and their priests and acolytes sold into training at more efficient and productive companies. Yea, and there shall be a great rejoicing upon the 'Net in those days.But like many monopolies, they are being attacked and reviled on many fronts, and while they may last longer than many other monopolies, they will eventually either go under or be broken up - and I am not talking about government interference. Anyone who wonders what I mean should read what Peter Drucker has to say about monopolies some time.
In short, don't worry, the "Evil Empire" will go down for the same reason the other "Evil Empire" (USSR) did.