August 07, 2008, 07:41:10 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length

There are currently 0" users in chat
News: We have a gallery that you can use to upload pictures. Do you have an image you want to share? Do you have a problem that is hard to describe?
 
 
  Website   Home   Help Search Affiliate Chat Calendar Members Tags Links Gallery Media Center Login Register  
Gł Solutions Network
In short, the goal of Gł Solutions is in the title. We attempt to define technology in easily understood terms.
From the end-user to the entrenched and battle scarred professional - we all have questions. And answers.
We attempt to answer these questions - in a round-about fashion - as this: "How can technology help?"
MAIN SITE BLOG Main Site Search HOSTING PRIVACY CONTACT ABOUT



Digg This!
Subject Statistics
Topic: Privacy Information... Please Read. Replies: 5 posts
Read 1028 times 0 Members and 1 Guest are viewing this topic.
Pages: [1]   Go Down
  Reply  |  New Topic  |  Send this topic  |  Print  
Author Topic: Privacy Information... Please Read.  (Read 1028 times)
 
0 Members and 1 Guest are viewing this topic.
KGIII
Official Code Wrecker
Administrator
Dedicated Poster
********

Karma: +15/-2
Offline Offline

Mood:

Gender: Male
OS: Vista, XP, Ubuntu
CPU: 2x AMD64 4800+
RAM: 3 GB
HDD: 500 GB (Raid0)
Posts: 11108


 

Topic starter
Yes, yes I can.


View Profile WWW
« on: November 12, 2006, 10:12:14 AM »

I haven't any control over this and I'm just seeing this now. No worries, I respect your privacy.

Messages sent in/out/from/via the Private Message function on this server are stored in plain text in the SQL databases. This means that anyone who can access the SQL databases (limited by IP, strong password, and encryption when stored locally) can read any of the "Private Messages" you send to each other.

In theory it is as close to 100% secure as one can make it. However - I still feel that full disclosure and informed choices are the best policy with security and privacy.

If you have ANYTHING that you are concerned about please feel free to Private Message me. *grins*

For the record, frankly, nothing one does online is ever private or completely secure. That being said, all interactions with the databases are limited to the localhost and this should prevent anybody other than those people directly affiliated with Gł Solutions from accessing the data. (If they can, well, the last thing they're going to be curious about is your private messages. You'll have to trust me on that one.)

What is MORE secure? Nothing really. I will consider changing it if I can safely do so without impacting server performance. I have added a modification which allows you to email one another via the email buttons - those are not, to the best of our awareness - logged anywhere for very long though the record will still exist in the logs as outbound packets via sendmail protocol.

Is this any different then anywhere else, anything else, or any other site or forum? No, not really. I'm probably just the only one who's really wanting to make you aware of it now that I've noticed the information is retained and I also want to ensure that you know that all backups are stored (data at rest) in an encrypted state.

Possible solutions include using the MD5 hash to disable the plain text storage of the private messages. With such a large volume of data that becomes a rather difficult process and is likely to be compute cycle intensive to the point where it would certainly be considered abusive by myself and I'd have to then ban myself and kick me off the server this is housed on.

Just so you are aware, this doesn't affect passwords or the likes. All passwords are encrypted using the MD5 hash which prevents them from being reversed. (They could be looked up, of course, but those records are pretty pathetic and not entirely accurate so there's no cause for alarm with anything that is security related, it is just a matter of privacy and now that I'm aware of this situation I wanted to ensure that you heard about it, knew about it, and were able to make an informed choice as to the content you put into the private messages.)

Again, if you have any concerns, please contact me via the private message function or via email at kgiii@kgiii.info and we'll work on it from there. As this is an abnormal situation this post will remain unlocked for the time being and those wishing to add comments, ask questions, or state their feelings are welcome to do so here as well.

Please understand me when I say that I will personally continue to educate myself on this subject until I'm more certain of the methods used but at this time it appears as if all sent, saved, read, and unread PMs are stored - even after being "deleted" - in plain text in the database. From a forensic view that is a good thing and it will help to ensure that we're able to investigate complaints should they ever happen however it is something I feel very strongly about and would like to know that you are all aware of the circumstances. Additionally - it is an assumption, at this time, that when I clear out data via the admin interface that older private messages are then deleted from the data on the server. I can not confirm that at this time and that still does not completely address the fact that the data is also stored locally, though encrypted, for 6 months on a weekly schedule. So, please, remember that regardless of the security involved you should not ever enter any information into a Private Message that you would not want to be made public.

KGIII
Gł Solutions
« Last Edit: November 12, 2006, 10:27:42 AM by KGIII » Report to moderator   Logged
Gł Solutions - Technology Defined
« on: November 12, 2006, 10:12:14 AM »
Reply with quoteQuote


 Logged
runswithscissors
Helpers
Dedicated Poster
********

Karma: +3/-0
Offline Offline

Mood:

Gender: Female
Posts: 1060


Libra  

Insert Wit Here


View Profile
« Reply #1 on: November 12, 2006, 01:44:38 PM »

Quote from: KGIII
Possible solutions include using the MD5 hash to disable the plain text storage of the private messages. With such a large volume of data that becomes a rather difficult process and is likely to be compute cycle intensive to the point where it would certainly be considered abusive by myself and I'd have to then ban myself and kick me off the server this is housed on.

Hmmm... that seems to defeat the purpose. Don't do that.

I'm glad, however, that you let us know about this.

I'll be sure to regulate stories of my weekend escapades to my LiveJournal account where everything is TOTALLY SAFE.

I also believe in the Tooth Fairy and the HogFather.

« Last Edit: November 12, 2006, 01:53:57 PM by runswithscissors » Report to moderator   Logged
KGIII
Official Code Wrecker
Administrator
Dedicated Poster
********

Karma: +15/-2
Offline Offline

Mood:

Gender: Male
OS: Vista, XP, Ubuntu
CPU: 2x AMD64 4800+
RAM: 3 GB
HDD: 500 GB (Raid0)
Posts: 11108


 

Topic starter
Yes, yes I can.


View Profile WWW
« Reply #2 on: November 12, 2006, 01:57:41 PM »

I felt compelled to inform people and, well, I always do what I feel like doing. Funny though, people usually complain if you're the type of person to always do what you want. Wink
Report to moderator   Logged
Element
Helpers
Hero Member
*****

Karma: +2/-5
Offline Offline

Mood:

Gender: Male
OS: Windows XP, Ubuntu
CPU: AMD Athlon 64 3200 OC to 2.4
RAM: 1 GB
HDD: 120 GIG, 80 on server.
Posts: 189


Aquarius   Red Serpent - Survives Life ForceCrystal

Owner of UTech


View Profile WWW
« Reply #3 on: November 12, 2006, 01:58:58 PM »

The hog what? And yes, the tooth fairy does exist. She came once dressed as my mom a few times. Then as my dad too. Kinda strange.
Report to moderator   Logged

KGIII
Official Code Wrecker
Administrator
Dedicated Poster
********

Karma: +15/-2
Offline Offline

Mood:

Gender: Male
OS: Vista, XP, Ubuntu
CPU: 2x AMD64 4800+
RAM: 3 GB
HDD: 500 GB (Raid0)
Posts: 11108


 

Topic starter
Yes, yes I can.


View Profile WWW
« Reply #4 on: November 12, 2006, 02:35:09 PM »

You don't know who the Hogfather is?

Hmm...

Terry Pratchett - Discworld. Wink

Read some of 'em. They're a riot.
Report to moderator   Logged
Gł Solutions - Technology Defined
« Reply #4 on: November 12, 2006, 02:35:09 PM »
Reply with quoteQuote


 Logged
runswithscissors
Helpers
Dedicated Poster
********

Karma: +3/-0
Offline Offline

Mood:

Gender: Female
Posts: 1060


Libra  

Insert Wit Here


View Profile
« Reply #5 on: November 12, 2006, 06:51:26 PM »

I felt compelled to inform people and, well, I always do what I feel like doing. Funny though, people usually complain if you're the type of person to always do what you want. Wink

I'm glad you told us, though it won't really affect anything I do here on this particular forum.

I'd have only been mad if you had, say, sold my info to Amway.
Report to moderator   Logged
Tags:
Pages: [1]   Go Up
  Reply  |  New Topic  |  Send this topic  |  Print  
 
Jump to:  

+ Quick Reply
With a Quick-Reply you can use bulletin board code and smileys as you would in a normal post, but much more conveniently.

Reminder:
Why not introduce yourself or register?
Powered by SMF 1.1.4 | SMF © 2006-2008, Simple Machines LLC | Sitemap
This page was magically conjured in about 0.256 seconds with 39 spell components. No animals were harmed in the making of this page.

Google visited last this page July 31, 2008, 01:39:38 AM