The Furious Angels

FA Discussion => General => Topic started by: Tbone on March 16, 2006, 08:19:24 pm

Title: Information Regarding Security Breach
Post by: Tbone on March 16, 2006, 08:19:24 pm
I thought I would make a post to clarify on some details that we've come to learn about a security breach on our website.

If you don't know by now, Trucidos/Abigor666/Psycidelicos posted a screenshot of our member-only forums. This is only the most recent evidence we've had that our security may be in question. We have known for a while, for instance, that there had been unauthorized access to our staff forums. We believe we have cleared up how this security breach happened and are relatively sure that our website is now secure.

Here's what happened. Orien's user account was compromised when an admin of another faction's website retrieved Orien's password from their database (he had registered with their forums). This person has come clean and given us specific details. Trucidos discovered that this person had access and effectively blackmailed this person into providing him with info from our site. He lost access a few weeks ago when we became suspicious and I required every staff member to change their password on the website.

Trucidos used information that he was gathering from our site (specifically my proposal to create a hidden LESIG forum for anyone who might have gotten in to discuss things privately amongst themselves without breaking their NDA) and attempted to twist it to get us in trouble. This has actually opened a huge can of worms for him, for not only has his lies already been cleared up, but he has now provided evidence of unauthorized access to a private site via means of hacking and blackmail. On top of this, he has provided evidence that he is indeed Psycidelicos, an account that was banned by Monolith, and that he is breaking TOS by circumventing this ban.

The person he was blackmailing grew to have respect for our faction (probably by perusing these forums) and obviously has grew to dislike Trucidos. This should play in our favor for the things to come.

One more thing I want to address quickly. When we first became aware of a possible spy, there was circumstantial evidence that pointed to Bentonn. For this reason, he was removed from the faction. Obviously we made the wrong decision, and so we do apologize to Bentonn for not giving him the benefit of the doubt. Recently I've been talking with him about giving him a re-interview to get back in, so if you see him in-game, please tell him that we're anxious to try and get him back. This also clears Anamodiel, who we believed to be the same person who originally hacked Orien's account until we received a written confession. Both of these people should be interviewed without biased.
Title: Re: Information Regarding Security Breach
Post by: Manic Velocity on March 16, 2006, 08:36:41 pm
I've been thinking for some time that it wouldn't be a bad idea to reinstate the "No posting on the MxO forums" rule.  I know very few of us do anyway, but there are times when attempting to defend ourselves publicly can have the opposite effect.

Back when I first joined, the rule was already in place so I don't really know the circumstances of why.  But with the way the MxO forums were/are, it didn't seem like a bad idea either way.  To quote one of my luminaries, Calvin Coolidge: "If you don't say anything, you won't be called on to repeat it."

If I'm the only one who feels this way, then I'll shut up.  :)
Title: Re: Information Regarding Security Breach
Post by: Avzeke (Khr0n1k) on March 16, 2006, 08:53:25 pm
yeah that was back during the...shaper incident......
Title: Re: Information Regarding Security Breach
Post by: Styan on March 16, 2006, 09:24:54 pm
I am in full support of the no talk rule. (hardly do it as it is... its just not worth it)
Title: Information Regarding Security Breach
Post by: Broin on March 16, 2006, 09:32:54 pm
Needless to say folks do not post any information about this on the MXO boards and do not let this leave the faction, as things are still in the works
Title: Information Regarding Security Breach
Post by: Da6onet on March 16, 2006, 10:27:00 pm
What exactly happened during the shaper event to enrage so many FA haters?

I also believe that no posting on the MxO boards is not quite the right course of action. I believe TBone should be the ONLY person allowed to post on the public boards regarding things like this.

Boards which are discussing game developement, marketplace, player events, etc, those aren't really going to cause too much harm if we all post to places/subjects like that (I hope!)

In the absence of light, darkness prevails
-Buddha


coolidge obviously wasn't a buddhist :-P
Title: Information Regarding Security Breach
Post by: Manic Velocity on March 16, 2006, 10:33:21 pm
Quote from: "Da6onet"
coolidge obviously wasn't a buddhist :-P


But he was an introvert, of which I am also.  :)
Title: Information Regarding Security Breach
Post by: Adad on March 16, 2006, 11:46:11 pm
I like that idea. Let the man do our speaking outside of these forums.
Title: Information Regarding Security Breach
Post by: Tbone on March 16, 2006, 11:56:59 pm
Quote from: "Da6onet"
What exactly happened during the shaper event to enrage so many FA haters?


The event consisted of shaking hands with a character, which initiated him to follow you to a subway location. Meanwhile the other orgs were attempting to attack you and "steal" the "shaper". Why did everyone get mad at us? Apparently at the time there was a bug with rez that unflagged you for PvP after you had been rezzed. The first time I got the shaper I had already been killed and rezzed, and thus could not be attacked. I wasn't aware of the bug, and things were so hectic that I didn't look at area chat (a lot of people were yellin "sploits"). It was believed that we purposely /suicided and rezzed ourselves to become immune when, in reality, I was just ignorant to that bug.

After the first shaper thingie happened (there were 6 of them) and I realized the bug, I announced in TS to attack someone after you are rezzed so that you are flagged. Gabriel, however, had died and been rezzed and either got caught up in the moment and forgot or made a bad judgement call and nabbed the shaper. Sad thing is the rest of us couldn't tell because he always appears friendly for us. So that was two strikes...

The third time one of our newer members found us and joined in the action. He was level 9, so he wasn't tagged by default. Talk about a loophole in the event. Not planned, though.

In the end we should have been more careful to make sure that none of us did anything that could even be considered unfair, but the whole thing was blown way out of proportion to make it look like we had premeditated exploiting the event, etc. etc. The FA haters had a FIELD DAY with it and still bring it up to this day because it's the only thing they can thing of that even remotely makes us look bad.
Title: Information Regarding Security Breach
Post by: Styan on March 17, 2006, 12:01:09 am
At the same time this was the beginning of the end of Monolith.
Title: Information Regarding Security Breach
Post by: Kosila on March 17, 2006, 01:29:05 am
Well I'm glad this is mostly cleared up.
Title: Information Regarding Security Breach
Post by: Anonymous on March 17, 2006, 02:49:07 am
I'll contact Anamodiel since we have correspondence already, I know he's anxious to prove himself
Title: Information Regarding Security Breach
Post by: Ash on March 17, 2006, 10:42:20 am
Anamodiel is a female character, not sure if it's a "real" female though.
Title: Information Regarding Security Breach
Post by: Anonymous on March 17, 2006, 02:30:57 pm
It's not ;)
Title: Information Regarding Security Breach
Post by: ArchNemesis on March 17, 2006, 07:26:36 pm
Sadness T_T
Title: Information Regarding Security Breach
Post by: Lits on March 18, 2006, 01:14:18 am
Indeed
Title: Information Regarding Security Breach
Post by: Anonymous on March 18, 2006, 01:15:19 am
I guess it could pretend to be?

XD
Title: Information Regarding Security Breach
Post by: Heironymus on March 18, 2006, 01:55:31 am
Just a thought.. if we want Bentonn to have a second chance.. we kinda need to get him in TS... cuz..http://mxoboards.station.sony.com/matrix/board/message?board.id=recruiting&message.id=3616
Title: Information Regarding Security Breach
Post by: Lithium on March 18, 2006, 09:30:40 am
I don't get it Bentonn was level 25 came around for 5 mins asked a million questions and left.... we want people like that?
Title: Information Regarding Security Breach
Post by: Lits on March 18, 2006, 09:32:24 am
Seems we need to be quick about this...
Title: Information Regarding Security Breach
Post by: Bellthazor on March 18, 2006, 10:15:05 am
Lithium wrote
Quote

I don't get it Bentonn was level 25 came around for 5 mins asked a million questions and left.... we want people like that?


Just tell him that we would want more participation out of him. Again we do have real lives but everyone is usually on during the weekends and or atleast 1-2hours during the week. Just my 2cents.  :p
Title: Information Regarding Security Breach
Post by: Tbone on March 18, 2006, 12:46:00 pm
Quote from: "Lithium"
I don't get it Bentonn was level 25 came around for 5 mins asked a million questions and left.... we want people like that?

I'm asking for a re-interview. Whether you vote yes or no is a different matter.
Title: Information Regarding Security Breach
Post by: Anonymous on March 18, 2006, 01:01:40 pm
Quote from: "Lithium"
I don't get it Bentonn was level 25 came around for 5 mins asked a million questions and left.... we want people like that?


Wasn't that Woodgrain?  I'm confoosed.
Title: Information Regarding Security Breach
Post by: Styan on March 18, 2006, 03:07:11 pm
Quote from: "Destyn"
Quote from: "Lithium"
I don't get it Bentonn was level 25 came around for 5 mins asked a million questions and left.... we want people like that?


Wasn't that Woodgrain?  I'm confoosed.


Woodgrain was the obnoxious one that acted like he didn't know much about computers. (Maybe he didn't??) Woodgrain was very "against the grain".
SimplePortal 2.3.8 © 2008-2025, SimplePortal