Cyan's Server "hacked"?

Anything that isn't directly related to Age Creation but that might be interesting to Age developers.

Re: Cyan's Server "hacked"?

Postby Whilyam » Sun Mar 14, 2010 6:34 am

Trylon wrote:I'm a bit suprised about how worked up everyone got about it. The joke seemed harmless enough to me. Hardly worth the lifelong banning some people "kindly requested".

Then again, the need for or value of memorials and graves is a bit alien to me, me and my family and friends never needed or valued them to remember the dead. Even in real life, grafitti on a tombstone has no more effect on me than grafitti on a piece of art or a wall. (To be clear: I don't like grafitti)

Well, correct me if I'm wrong, but if someone can alter the vault like this they can trigger malicious code as well. I'm probably wrong, though.
User avatar
Whilyam
 
Posts: 1023
Joined: Sat Sep 29, 2007 5:55 pm

Re: Cyan's Server "hacked"?

Postby Tahgtahv » Sun Mar 14, 2010 7:44 am

You are wrong. The worst someone could do is crash the server or crash the client.
Proud member of the Guild of Inkmakers
Tahgtahv
 
Posts: 25
Joined: Fri Nov 16, 2007 9:45 pm

Re: Cyan's Server "hacked"?

Postby diafero » Sun Mar 14, 2010 7:47 am

At least in POTS/UU it is not possible to run malicious code on the server or other machines. However, within the game, you are god - an AdminKI for MOUL is certainly possible.
I prefer e-mails to "diafero arcor de" (after adding the at and the dot) over PMs.

"Many people's horizon is a circle with a radius of zero. They call it their point of view."

Deep Island Shard | Offline KI
diafero
Deep Island Admin
 
Posts: 2972
Joined: Mon May 05, 2008 5:50 am
Location: Germany

Re: Cyan's Server "hacked"?

Postby Nadnerb » Sun Mar 14, 2010 11:39 am

Well, theoretically, the worst someone could do is create an infinite ref loop in the vault, and permanently crash the vault server until cyan goes into the database and extracts the bad refs with sql. (that is, unless the moul vault servers are smarter than the UU vault servers, which is possible)

Alternatively, if they wanted to be really, really, really evil, they could go about renaming players and ages and haphazardly deleting refs, thus making the vault entirely impossible to recover (without rolling back to a backup copy) and highly unusable.
Last edited by Nadnerb on Sun Mar 14, 2010 11:41 am, edited 1 time in total.
Image
Live KI: 34914 MOULa KI: 23247 Gehn KI: 11588 Available Ages: TunnelDemo3, BoxAge, Odema
Nadnerb
 
Posts: 1057
Joined: Fri Sep 28, 2007 8:01 pm
Location: US (Eastern Time)

Re: Cyan's Server "hacked"?

Postby BAD » Sun Mar 14, 2010 11:40 am

Tahgtahv wrote:You are wrong. The worst someone could do is crash the server or crash the client.


Before people jump on this.....

Cyan most certainly is backing up the server data almost constantly, so if the server did crash or get corrupted, they could easily fall back on a backup.
BAD is as good as he gets
User avatar
BAD
 
Posts: 832
Joined: Sat Sep 29, 2007 9:44 am

Re: Cyan's Server "hacked"?

Postby Nadnerb » Sun Mar 14, 2010 11:43 am

This is true, but any such action would still cause significant downtime during the restoration process, and Cyan would most likely have no log of who did it, so they would be free to do it again when the servers came back up.
Image
Live KI: 34914 MOULa KI: 23247 Gehn KI: 11588 Available Ages: TunnelDemo3, BoxAge, Odema
Nadnerb
 
Posts: 1057
Joined: Fri Sep 28, 2007 8:01 pm
Location: US (Eastern Time)

Re: Cyan's Server "hacked"?

Postby BAD » Sun Mar 14, 2010 11:45 am

Nadnerb wrote:This is true, but any such action would still cause significant downtime during the restoration process, and Cyan would most likely have no log of who did it, so they would be free to do it again when the servers came back up.


Yes, I just made sure that was said right away so we don't get people freaking out that the server will get corrupted and Cyan can't do anything about it.
BAD is as good as he gets
User avatar
BAD
 
Posts: 832
Joined: Sat Sep 29, 2007 9:44 am

Re: Cyan's Server "hacked"?

Postby Karkadann » Tue Mar 16, 2010 8:56 am

Im kinda wondering How Cyan feels about the incident, and whether it pushed open source back further or not. I believe they have a surplus of money and will be continuing to work on open source when they have a surplus of time. Its definitely a security issue, that needs to be dealt with, one more thing to do I guess before releasing open source.

If who ever did this is looking forward to getting open source I feel they may have just shot themselves in the foot, and have lengthened the path they have to travel with said injury
I Don't Have A Cell Phone, I have Freedom!
User avatar
Karkadann
 
Posts: 1224
Joined: Sun Aug 02, 2009 10:04 am
Location: Earth

Re: Cyan's Server "hacked"?

Postby diafero » Tue Mar 16, 2010 9:48 am

Its definitely a security issue, that needs to be dealt with, one more thing to do I guess before releasing open source.
I would put it the other way around... the code is full of possible security leaks, everyone dealing with the internal functionality of the engine knows that Uru effectively has no measures to limit a user's privileges besides the dataserver, which can even be easily switched of in UU/Alcugs. There are some who can circumvent it for MOUL.
Basically, when you run a UU/Alcugs Shard, you trust your players not to do bad stuff with the others on your server, or with the vault. While a lot was changed for MOUL, this incident proves that the basics did not change. Cyan obviously does not have the resources to change that as that would require either a re-design of the game or some additional sanitizing layer in the server. Open-source is the only way to gain these resources.
I prefer e-mails to "diafero arcor de" (after adding the at and the dot) over PMs.

"Many people's horizon is a circle with a radius of zero. They call it their point of view."

Deep Island Shard | Offline KI
diafero
Deep Island Admin
 
Posts: 2972
Joined: Mon May 05, 2008 5:50 am
Location: Germany

Re: Cyan's Server "hacked"?

Postby Karkadann » Tue Mar 16, 2010 10:20 am

Well personally If I were Cyan and I was gonna Open source Uru live I would need time to not only do the open source thing to Uru Live and prepare it for distribution. I would need time to work all the bugs out so when I do release it I would be releasing a Quality product instead of the technical equivalent of swiss cheese. If it where not for the disrespectful aspect of this whole situation I don't think it would have been a issue.

My personal option of this situation is to me it seems like someone did not get what they wanted when they wanted it and this is the technical equivalent of a temper tantrum. They could have picked something a little less disrespectful.
I Don't Have A Cell Phone, I have Freedom!
User avatar
Karkadann
 
Posts: 1224
Joined: Sun Aug 02, 2009 10:04 am
Location: Earth

PreviousNext

Return to Off-Topic Discussion

Who is online

Users browsing this forum: No registered users and 1 guest

cron