mersenneforum.org

mersenneforum.org (https://www.mersenneforum.org/index.php)
-   Forum Feedback (https://www.mersenneforum.org/forumdisplay.php?f=61)
-   -   Forum Insecurity (https://www.mersenneforum.org/showthread.php?t=14164)

davar55 2010-11-06 14:31

Forum Insecurity
 
Attention super moderator. There's a potential security flaw in the forum.

:wink:

You are aware that whenever one logs off, one is prompted to delete a
random account.

If this were a true opportunity for an attacker to wreak havoc on the forum
by repeatedly logging in and out and eventually deleting all our accounts
randomly, I would fear for the forum.

I'm sure this is not so.

However, imagine a stupid davar55 who tries to bring down the forum by just
such a denial of service attack. Repeatedly logging in and logging out.
One such davar55 is no danger. But suppose there's a team of davar55s (if there
could be such a thing) all trying to delete our accounts by repeated
login/logouts simultaneously. This might actually affect forum accessibility,
mightn't it? That random account message is a davar55 magnet.

Or maybe it's davar55 flypaper?

Uncwilly 2010-11-06 14:55

I think that the mods here do a fine job keeping Unc[spoiler]willy[/spoiler]s out in the first place.

Prime95 2010-11-06 15:59

I don't think the problem is too severe. In the past 6 years or so, my account has only been deleted twice.

retina 2010-11-06 16:04

And of course the prankster that is doing the repeated logging out eventually ends up deleting their own account. So the problem neatly solves itself.

davar55 2010-11-12 18:10

Didn't intend to pursue this but it looks like
someone or something has swallowed a certain
word I overused in the OP and won't reuse here.
I guess the forum is protected by a 'certain word' gobbler.

Speaking of gobbling, Happy early Thanksgiving everyone.

Xyzzy 2010-11-13 04:58

The censor function is not enabled for the forum. Perhaps a moderator or super moderator edited your post?

davar55 2010-11-13 14:13

Oh no, that can't be. Why would the super moderator pay unserious
attention to what was only a thinly veiled bit of levity concerning an
arguably totally unimportant solvable problem? I mean, just as no one
could damage the forum just by logging in and out, even in heavy
numbers (and this forum deals with the heaviest numbers), so too no
moderator would actually resort to physically editing a contributed post
when this could be done by, say, an enabled auto-censor function.
Now would they? We weren't aware that the T-word itself was to be
treated as expungeable, or we wouldn't have thrown it around so much.

Happy T-day (I mean Thanksgiving).

Xyzzy 2010-11-13 22:48

:kitten:

davar55 2010-12-08 19:52

[quote]Oh no, that can't be. Why would the super moderator pay unserious
attention to what was only a thinly veiled bit of levity concerning an
arguably totally unimportant solvable problem? I mean, just as no one
could damage the forum just by logging in and out, even in heavy
numbers (and this forum deals with the heaviest numbers), so too no
moderator would actually resort to physically editing a contributed post
when this could be done by, say, an enabled auto-censor function.
Now would they? We weren't aware that the T-word itself was to be
treated as expungeable, or we wouldn't have thrown it around so much.

Happy T-day (I mean Thanksgiving).[/quote]

Sorry about this extra post, but I don't get that response.

Brian-E 2010-12-09 12:39

You're not seriously advocating an auto-censor function, are you? :smile:

Or are you?

They can produce [URL="http://www.rightwingwatch.org/2008/06/the_dangers_of_1.html"]ludicrous results[/URL] for which the athlete Tyson G** was made an inadvertent victim.

OK, that was not the subject of your original posting but it genuinely isn't clear to me how serious you were then either.

xilman 2010-12-09 14:48

[QUOTE=Brian-E;240939]You're not seriously advocating an auto-censor function, are you? :smile:

Or are you?

They can produce [URL="http://www.rightwingwatch.org/2008/06/the_dangers_of_1.html"]ludicrous results[/URL] for which the athlete Tyson G** was made an inadvertent victim.

OK, that was not the subject of your original posting but it genuinely isn't clear to me how serious you were then either.[/QUOTE]The [URL="http://en.wikipedia.org/wiki/Scunthorpe_problem"]Scunthorpe problem[/URL] strikes again. I thought that AOL's experiences some 14 years ago had indicated the fallout that can result from careless use of auto-Bowdlerizer software.

Paul


All times are UTC. The time now is 06:29.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2021, Jelsoft Enterprises Ltd.