|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
![]() ![]() |
| wikiwhistle |
Tue 4th December 2007, 3:24am
Post
#21
|
![]() Postmaster ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Regulars Posts: 1,928 Joined: Mon 26th Nov 2007, 2:17pm Member No.: 3,953 |
As far as I know and also my OH who has a degree in computer science and is very well versed in these issues, he said
"if they know of a way that normal-ranking members of a forum can gather other's IPs, I would LOVE to know about it "I suppose you could get it by getting the person to mail you using the emails that reveal their IP, using 'social engineering' but that would be a lot of effort if you wanted to do it for a lot of users. |
| dtobias |
Tue 4th December 2007, 4:47am
Post
#22
|
![]() Obsessive trolling idiot [per JzG] ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Regulars Posts: 2,213 Joined: Sun 11th Feb 2007, 2:45pm From: Boca Raton, FL, USA Member No.: 962 WP user page - talk check - contribs |
I'm the one there who called you a "doody-head", just to be silly... and to see if you were still watching. ![]() |
| Somey |
Tue 4th December 2007, 5:26am
Post
#23
|
![]() Can't actually moderate ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderators Posts: 11,814 Joined: Sat 17th Jun 2006, 7:47pm From: Dreamland Member No.: 275 |
As far as I know and also my OH who has a degree in computer science and is very well versed in these issues, he said "if they know of a way that normal-ranking members of a forum can gather other's IPs, I would LOVE to know about it :D " Well... theoretically, if you hosted your avatar on a domain you personally control, you could look at the raw access logs for that domain, data-mine all the requests for that specific image, and compare it to a similar list you generated from other images. We've known about that all along, and in fact we even deleted Wordbomb's sigs a couple of times just to make sure... but we've nevertheless resisted imposing strict controls on avatars, simply because it would make the place less fun. We also haven't received any complaints, really, except of course from Gary Weiss. Though that may only be because people aren't sufficiently aware of the issue, just like they're not sufficiently aware of the Gary Weiss issue... Now, whenever someone changes their avatar around here, one of us usually checks to see where it's coming from. But a really devious person could host their avatar on one site for a while and then change it to another after a few weeks, and we might not notice until it's - tragically - too late! Alkivar's idea of having all the images hosted locally is perfectly reasonable, except that it means exposing an FTP-accessible folder to the world, and there are ways that can be exploited, even though you'd have to be something of a hacker to grab the authentication. Still, if we were a non-controversial site, then we'd almost certainly do it that way, I suppose... The compromise alternative, which I've been dragging my arse on for two months, is to insist that people use one or more third-party image-hosting sites, such as imageshack and photobucket, that everyone can pretty much agree on. That, or else restrict themselves to what's in the avatar gallery. Again, not as much fun, but I suspect most people wouldn't mind - those sites are fairly easy to use. |
| Pumpkin Muffins |
Tue 4th December 2007, 5:50am
Post
#24
|
![]() Über Member ![]() ![]() ![]() ![]() ![]() Group: Regulars Posts: 656 Joined: Wed 28th Nov 2007, 4:48pm Member No.: 3,972 |
Wikipedia definitely logs referrers. They've run statistics on who's hitting WP from Google, for instance. You can see a sample of what Wikipedia logs here. In this case, I think Brion enabled some additional logging. |
| Moulton |
Tue 4th December 2007, 8:18am
Post
#25
|
![]() Anthropologist from Mars ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributors Posts: 10,220 Joined: Mon 29th Oct 2007, 9:56pm From: Greater Boston Member No.: 3,670 WP user page - talk check - contribs |
|
| guy |
Tue 4th December 2007, 11:04am
Post
#26
|
|
Postmaster General ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Inactive Posts: 4,294 Joined: Mon 27th Feb 2006, 8:52pm From: London Member No.: 23 |
QUOTE The cookies appear to declare the attacker as a logged-out User:MARMOT. So they can catch you even if you are logged out. |
| AB |
Tue 4th December 2007, 2:47pm
Post
#27
|
|
'...I will be generous and give you a week.' ![]() ![]() ![]() ![]() ![]() Group: Inactive Posts: 888 Joined: Tue 28th Aug 2007, 2:26am Member No.: 2,742 |
So which is more concerning, then? The idea that WP is logging referrers to sniff out who's following links from here, or the idea that people here are sneakily using offsite-hosted avatars or those little 1px tracking images to obtain IP's without anyone else knowing about it? I know we've been accused of looking at our own raw access logs to try and figure out who's visiting from WP, but that's just part of the usual JzG cabal disinformation campaign. (AS IF Selina or I would actually have the time or patience to sift through all that stuff!) Besides, look at the recent numbers down in the board footer... Everybody's dropping by nowadays. People who care about the privacy of their IP addresses should be using Tor or some other proxy. Your browser may be configurable to not show referrers. In Firefox, go to about:config and set Network.http.sendRefererHeader to 0. For Konqueror, use the following command: kwriteconfig --file ~/.kde/share/config/kio_httprc --key SendReferrer --type bool false Or you coud just edit the kio_httprc file with vim or emacs or something. If your browser does not allow you to hide referrers, there are proxies that can scrub it for you. QUOTE The cookies appear to declare the attacker as a logged-out User:[...]. So they can catch you even if you are logged out. So delete your WP cookies. This post has been edited by AB: Tue 4th December 2007, 3:06pm |
| Disillusioned Lackey |
Tue 4th December 2007, 2:52pm
Post
#28
|
|
Unregistered |
|
| Moulton |
Tue 4th December 2007, 3:14pm
Post
#29
|
![]() Anthropologist from Mars ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributors Posts: 10,220 Joined: Mon 29th Oct 2007, 9:56pm From: Greater Boston Member No.: 3,670 WP user page - talk check - contribs |
Cookies are not an entirely reliable source.
If one is using a public computer (say at a school or library), then an old cookie might have nothing to do with another person who comes along later and uses the same physical machine without logging in. |
| Aloft |
Tue 4th December 2007, 3:21pm
Post
#30
|
|
Please stop trying to cause trouble! ![]() ![]() ![]() ![]() Group: Regulars Posts: 322 Joined: Wed 26th Sep 2007, 5:40am Member No.: 3,239 |
|
| Jonny Cache |
Tue 4th December 2007, 3:22pm
Post
#31
|
|
τα δε μοι παθήματα μαθήματα γέγονε ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Contributors Posts: 5,100 Joined: Sat 9th Sep 2006, 1:52am Member No.: 398 WP user page - talk check - contribs |
Cookies are not an entirely reliable source. If one is using a public computer (say at a school or library), then an old cookie might have nothing to do with another person who comes along later and uses the same physical machine without logging in. Reliability !? Wikipediots don't need no stinkin reliability !!! Their policy is WP:BFABQL (Ban First And Block Questions Later). Jonny ![]() This post has been edited by Jonny Cache: Tue 4th December 2007, 6:44pm |
![]() ![]() |
|
Lo-Fi Version | Time is now: 25th 5 13, 5:43am |