Notices

"EDIT" post Feature removed

 
Thread Tools
 
Search this Thread
 
Rate Thread
 
Old 12-10-2011 | 12:48 PM
  #1  
Highway8's Avatar
Thread Starter
Registered RX8 Nut
iTrader: (11)
 
Joined: Jul 2007
Posts: 1,366
Likes: 8
From: Fairfield, CA
"EDIT" post Feature removed

Until today I had always been able to go back and edit or delete a post. Today I noticed that older post could not be edited or deleted. While I can see some merit to the change, I see more problems with it.

For 1, my thoughts and words are my own and even though I post them on a forum they will always be mine. I should be able to remove or edit them at my discretion. Unless I missed something, once I post something to a forum they do not become the property of the forum. ????

2- (and this is how I discovered the change) Some post are information or schedules that can change. This is especialy true for the 1st post of a thread, such as my Nor Cal Track Day Schedule.

Suggestion: Change it back, or add a request to edit post. The button is pressed and everything is identical to a regular post edit, except the change must be reviewed by a moderator before the change is made. This feature can only be used to correct information, up dates and changes but not for spelling corrections. Post can be deleted in a similar fashion and for similar reasons.
Old 12-10-2011 | 01:04 PM
  #2  
RIWWP's Avatar
Registered
iTrader: (2)
 
Joined: Oct 2007
Posts: 16,684
Likes: 261
From: Pacific Northwest
It's been like this for at least a few weeks, if not over a month. Basically the Admins found that some spammers were using the edit feature to insert spam and unwanted links into prior posts, often through account take-overs of existing members. So they enabled a feature that only allows edits for about 2 weeks or so after the post was originally made.


It is causing me issues in the New Owners thread too, but I can understand the reason for it. I believe they are working on a solution with IB.
Old 12-10-2011 | 01:06 PM
  #3  
Speed_8's Avatar
Registered User
 
Joined: Mar 2010
Posts: 1,089
Likes: 3
From: Ottawa, ON
I think even thou the thoughts are yours.. once posted they belong to the rx8club. Just like Facebook. Once u post a picture legally it belongs to Facebook
Old 12-10-2011 | 01:11 PM
  #4  
Highway8's Avatar
Thread Starter
Registered RX8 Nut
iTrader: (11)
 
Joined: Jul 2007
Posts: 1,366
Likes: 8
From: Fairfield, CA
Originally Posted by Speed_8
I think even thou the thoughts are yours.. once posted they belong to the rx8club. Just like Facebook. Once u post a picture legally it belongs to Facebook
Would not surprise me.
Old 12-10-2011 | 01:13 PM
  #5  
Highway8's Avatar
Thread Starter
Registered RX8 Nut
iTrader: (11)
 
Joined: Jul 2007
Posts: 1,366
Likes: 8
From: Fairfield, CA
Originally Posted by RIWWP
It's been like this for at least a few weeks, if not over a month. Basically the Admins found that some spammers were using the edit feature to insert spam and unwanted links into prior posts, often through account take-overs of existing members. So they enabled a feature that only allows edits for about 2 weeks or so after the post was originally made.


It is causing me issues in the New Owners thread too, but I can understand the reason for it. I believe they are working on a solution with IB.
Its always the spammers.

I figured there was a reason for it and I can understand it, I am just saying there needs to be a solution. So I hope your right that they are working on something.
Old 12-10-2011 | 01:15 PM
  #6  
RIWWP's Avatar
Registered
iTrader: (2)
 
Joined: Oct 2007
Posts: 16,684
Likes: 261
From: Pacific Northwest
Originally Posted by Speed_8
I think even thou the thoughts are yours.. once posted they belong to the rx8club. Just like Facebook. Once u post a picture legally it belongs to Facebook
Yes, of course. It's a massive conspiracy theory to steal all the information possible on the RX-8, to market it and make lots of money off of every new owner that pays through the nose to be able to research and read all day long without having to post up a new topic asking for something in the stickies. This conspiracy will eventually come to dominate the entire automotive world, and you will be unable to avoid involving yourself, becoming brainwashed to log in every day and contribute to the collective hive mind. Disconnecting yourself in an attempt to resist assimilation will result in immediate destruction of your engine.







...





Old 12-10-2011 | 01:24 PM
  #7  
zoom44's Avatar
Administrator
 
Joined: Jul 2002
Posts: 21,958
Likes: 115
From: portland oregon
if you need a change to an OP of an event thread just send to me or one of the other mods and we'll take care of it for now. in fact pm me and I might be able to give you "privileges" to that particular thread or forum. I did it for Phil for WHIVSIV
Old 12-10-2011 | 01:29 PM
  #8  
RIWWP's Avatar
Registered
iTrader: (2)
 
Joined: Oct 2007
Posts: 16,684
Likes: 261
From: Pacific Northwest
Mind giving me that privilege for my New Owners thread?

It's the only old thread I go back to edit.
Old 12-10-2011 | 01:31 PM
  #9  
jobidia's Avatar
Registered User
 
Joined: Dec 2011
Posts: 20
Likes: 0
So if I understand, because of a bug in the software and/or the fact the IB doesn't enforce the members to create a strong password, the members are handicapped with a 2 week edit grace period so spammers cannot take advantage of the weaknesses.

Due to the incompetence of IB technical team to perform software updates and create acceptable security policies it's long term members must be the ones that suffer? The ones that provide the kernal knowledge and make this site worth coming too.
Old 12-10-2011 | 01:37 PM
  #10  
RIWWP's Avatar
Registered
iTrader: (2)
 
Joined: Oct 2007
Posts: 16,684
Likes: 261
From: Pacific Northwest




It's not a "bug". It's an intended bit of software. This is just being exploited by some spammers, and IB has to take steps to figure out a better way of doing it.


It's like driving a car. The steering wheel is intended to control the direction of the car. Everyone uses it (usually). One person using it to deliberately crash into another car does not mean that steering wheels are inherently flawed.

How about we remove keyboards? Input methods. Make everyone unable to type. I'm sure that would prevent spammers.


It's not "incompetence" for someone to design a method of communication, and then someone else use all the intended features of that method to communicate unwanted material. Hell, plenty of newbies use it to generate unwanted communications all day long!




But yes, likely they will end up coming up with an answer that satisfies no one, causes problems, and then later correct it to something that works. (After all, I'm not aware of anyone getting it right the first time)
Old 12-10-2011 | 02:26 PM
  #11  
StealthTL's Avatar
Metatron
iTrader: (1)
 
Joined: Mar 2003
Posts: 7,284
Likes: 175
From: A Pacific Island.
Plenty of forums don't allow editing after a brief period.

.....makes for stupid discussions if someone can edit a week old post and claim "I never said that"
Old 12-10-2011 | 02:54 PM
  #12  
Speed_8's Avatar
Registered User
 
Joined: Mar 2010
Posts: 1,089
Likes: 3
From: Ottawa, ON
Originally Posted by RIWWP
Yes, of course. It's a massive conspiracy theory to steal all the information possible on the RX-8, to market it and make lots of money off of every new owner that pays through the nose to be able to research and read all day long without having to post up a new topic asking for something in the stickies. This conspiracy will eventually come to dominate the entire automotive world, and you will be unable to avoid involving yourself, becoming brainwashed to log in every day and contribute to the collective hive mind. Disconnecting yourself in an attempt to resist assimilation will result in immediate destruction of your engine.

well you are obviously taking what I said out of proportion..glad you wasted your time replying to my comment
Old 12-10-2011 | 03:00 PM
  #13  
RIWWP's Avatar
Registered
iTrader: (2)
 
Joined: Oct 2007
Posts: 16,684
Likes: 261
From: Pacific Northwest
Does that mean I get to waste more time?



Seriously though, posting something in public doesn't make it anyone elses "property" and more than you retain "ownership" of it when you post it in the first place. It becomes free domain. IB has no interest in trying to legally retain "ownership" of forum posts and content.
Old 12-10-2011 | 03:37 PM
  #14  
jobidia's Avatar
Registered User
 
Joined: Dec 2011
Posts: 20
Likes: 0
Originally Posted by RIWWP
It's been like this for at least a few weeks, if not over a month. Basically the Admins found that some spammers were using the edit feature to insert spam and unwanted links into prior posts, often through account take-overs of existing members. So they enabled a feature that only allows edits for about 2 weeks or so after the post was originally made.


It is causing me issues in the New Owners thread too, but I can understand the reason for it. I believe they are working on a solution with IB.
Originally Posted by RIWWP




It's not a "bug". It's an intended bit of software. This is just being exploited by some spammers, and IB has to take steps to figure out a better way of doing it.


It's like driving a car. The steering wheel is intended to control the direction of the car. Everyone uses it (usually). One person using it to deliberately crash into another car does not mean that steering wheels are inherently flawed.

How about we remove keyboards? Input methods. Make everyone unable to type. I'm sure that would prevent spammers.


It's not "incompetence" for someone to design a method of communication, and then someone else use all the intended features of that method to communicate unwanted material. Hell, plenty of newbies use it to generate unwanted communications all day long!




But yes, likely they will end up coming up with an answer that satisfies no one, causes problems, and then later correct it to something that works. (After all, I'm not aware of anyone getting it right the first time)
Mr. RIWWP please don't shake your head at me.
My point in the end was that IB's assets are this audience. Yet there interim solution is to but the burden of inconvenience on that audience.

And you are right, no one typically gets it right the first time but IB is lacking is some of the most basic security practices which are known to work, easy to implement and relatively cheap. Like the steering wheel lol

First, from the above quote of yours you sort of implied it might have been a bug/exploit of the edit button but mostly it was account take overs.
This is why I suggested perhaps (with an and/or) software bug.
However that is not the case so it would seem, so fine I didn't read it that way.

But this makes it worse in a way. (and I still say security incompetence)
IB brands has now had a issue with unauthorized account take overs and they didn't say anything to the community?

Responsible disclosure would have been to notify the users (forum members) that a preach of security had occurred and we suggest the forum members to change their passwords immediately.
Even something this simple. It's this community that makes IB money, what does it say about them if they don't even have the respect to tell us that our account and passwords have been comprised.
I wonder how many users use their same passwords for more than one account? Would be nice to tell them to change their passwords.
Have all our emails now been harvested?

Simple security policy that should have been put in place?
While we are thinking of passwords because IB uses no strong password enforcement you could probably use a list of the most common passwords to login to a users accounts.

Which brings us to the login ID which is the same as the User ID ... bingo I now have a list of valid accounts then I could script the most common passwords against and try and login. kewl.

But wait there is more. How many login attempts do I get? Dunno I've not tried but I bet it's a lot before the account gets locked if indeed this is even in place.
(I bet there is no account lock out with failed login attempts)

But wait there is more! Have you ever heard of Firesheep? Session hijacking at open wifi hot spots, like coffee shops and airports, you know.

The Twitters and Facebooks had a real problem with this as they "use to" offer un-encrypted login. Firesheep this simple open source application that allowed you to sidejack these session cookies which you could then assume their identity.
(ngrep is another application used to scrap unencrypted wifi data)

Furthermore I would suspect a spammer could set in a coffee shop or something and just harvest all the un-encrypted logins for use later.

All these security principles are not new, not even close to being new. The hardest one, and costing the most $$$ is setting up the https server for encrypted logins.

Mr RIWWP with respect I am saying that IB should be more responsible about security and have some respect of the information they hold about their members. (as little as it is)

I hope IB doesn't run anything important with real information.
eeek

That's it, makes me wonder why a solution is taking so long to implement.
What did you say, almost a month now?

Last edited by jobidia; 12-10-2011 at 03:53 PM. Reason: weird multi multi multi quotes
Old 12-10-2011 | 03:46 PM
  #15  
RIWWP's Avatar
Registered
iTrader: (2)
 
Joined: Oct 2007
Posts: 16,684
Likes: 261
From: Pacific Northwest
The account take-overs that I have seen evidence of myself all appeared to be in the nature of someone's password getting compromised on an individual basis. Either through having keyloggers on their system or wifi hijacking, etc... I am not aware of anyone breaching IB's data and mining passwords. If they did, I think we would see this on a significantly larger scale.

I am sure some of it is where the spammers create accounts themselves, create posts that aren't spam and just sit there dormant, and then re-edit later trying to get their spam out. Nothing much you can do about that security other than (the needed) increase in registration verification methods.

I also don't see it as much of an inconvenience to more than a handful of people. It doesn't remove the edit button, as you can see. It just adds a timer, so that after about 2 weeks, you can't edit any more. Very few of us on the boards have a reason to edit posts that old.

And Zoom pointed out that they can get around this issue for individual people and individual threads.

I 100% get what you are saying, that there are plenty of security methods out there. And I agree, IB hasn't really bothered to implement many of them. I was mostly just reacting to your implication that them allowing someone to edit their post is "incompetence."

Your 2nd post re-directed that label to an area more fitting, their overall security plan.
Old 12-10-2011 | 03:49 PM
  #16  
jobidia's Avatar
Registered User
 
Joined: Dec 2011
Posts: 20
Likes: 0
Originally Posted by StealthTL
Plenty of forums don't allow editing after a brief period.

.....makes for stupid discussions if someone can edit a week old post and claim "I never said that"
True enough.
Still I've seen a lot of threads where the first post is maintained.

Like RIWWP's and Green04 First Hundred dollar thread.

I see a lot of people quoting posts, sort of a self preserving system.

I've been on plenty of forums and so I do agree with you but you know the saying.

"It's easier to give users functionality than it is to take it away"
Old 12-10-2011 | 03:55 PM
  #17  
jobidia's Avatar
Registered User
 
Joined: Dec 2011
Posts: 20
Likes: 0
Originally Posted by RIWWP

Nothing much you can do about that security other than (the needed) increase in registration verification methods.


Like this idea, often labor intensive to implement and maintain.
Old 12-11-2011 | 12:07 AM
  #18  
zoom44's Avatar
Administrator
 
Joined: Jul 2002
Posts: 21,958
Likes: 115
From: portland oregon
first of all. Ib didnt find it- we did. the mod staff noticed a few ****/spam links creeping into sigs. a member who was effected noticed it alerted us and gave us some information. someone found that perhaps a script had been run that caused the "infection" we alerted IB about it who then said they'd get to work on it. I instigated the no edit after two weeks period (its actually after 'x" number of hours but i did the math( ask anyone - me doing the math is scary i dont do math) and figured roughly 15 days.

has it been a month? i dont know i havent really checked back on it since theres lots of stuff going on forum wise and personal life wise to keep me busy that this just isnt front and center on the radar. combine that with part time seasonal side job im working and the fact that this effecting about 5 forum members including riwwp and highway its just not abig deal for us to work around for awhile.

there is plenty of security available . some we use some we dont to make the forum user friendly. Elara for instance spend ALLOT of time with the new users when she can filtering through them. thats labor intensive and a complete bore. we could enforce strong passwords right from the admin cp but for why? to stop a few errant spam links once in a blue moon while inconveniencing everyone?

there is no need for massive wholesale contact with members to change passwords etc. or really any need for an announcement. we identified a problem. IB was alerted. itll be fixed. at some point ill go back and turn the edit time length off.

except maybe for anyone who has been here less than a month who complains about it being a burden to long time members
Old 12-11-2011 | 12:44 AM
  #19  
StealthTL's Avatar
Metatron
iTrader: (1)
 
Joined: Mar 2003
Posts: 7,284
Likes: 175
From: A Pacific Island.
Shows how intertube savvy I am (does anyone under 70 still say 'savvy'?)

I just noticed the exploit today....
Old 12-11-2011 | 08:31 AM
  #20  
Mazurfer's Avatar
Surf Hard, Drive Hard
 
Joined: Feb 2007
Posts: 7,840
Likes: 12
From: Indialantic, Florida
Originally Posted by zoom44
except maybe for anyone who has been here less than a month who complains about it being a burden to long time members
Touche'

Lots of long semi-in-depth posts for a newb. I'm all for making things better, but jeez. Need life?
Old 12-11-2011 | 03:51 PM
  #21  
ASH8's Avatar
Super Moderator
 
Joined: Apr 2005
Posts: 10,869
Likes: 327
From: Australia
And yeah, many other forums prevent any Editing after time.
Old 12-11-2011 | 06:30 PM
  #22  
Mazurfer's Avatar
Surf Hard, Drive Hard
 
Joined: Feb 2007
Posts: 7,840
Likes: 12
From: Indialantic, Florida
Yeah, but it kinda sucks because I had(have) a for sale thread made way back even before the "trader score" thing came about. I would edit this thread with updates and such, and hold it down to only one thread with history in it, so others could see that I sent what I said I would(etc.) and now I can't edit the first post.
I know I can copy it into buffer, create a new one, then paste the contents in, and then go back a delete the original, but that kind blows.............IMHO.


Using just one for sale thread since 1/4/2009. https://www.rx8club.com/rx-8-parts-sale-wanted-44/f-s-various-stuff-163778/

Last edited by Mazurfer; 12-11-2011 at 06:32 PM.
Old 12-11-2011 | 08:53 PM
  #23  
ken-x8's Avatar
Registered
 
Joined: Aug 2006
Posts: 5,027
Likes: 5
From: Northern Virginia
Originally Posted by RIWWP
Seriously though, posting something in public doesn't make it anyone elses "property" and more than you retain "ownership" of it when you post it in the first place. It becomes free domain. IB has no interest in trying to legally retain "ownership" of forum posts and content.
These days an author automatically keeps copyright ownership, unless there's an agreement otherwise. The Facebook deal was that they inserted that kind of clause into the user agreement. There were some photo sharing sites that tried the same stunt: having the user agreement declare that the site owned any photos that were uploaded.

If I were IB, the last thing I'd want would be ownership and responsibility for what gets posted here. Each of us is stuck with that.

Ken
 
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
rotorocks
Series I Tech Garage
47
05-11-2016 04:23 PM



You have already rated this thread Rating: Thread Rating: 0 votes,  average.


All times are GMT -5. The time now is 12:23 AM.