These forums have been archived and are now read-only.

The new forums are live and can be found at https://forums.eveonline.com/

EVE Technology Lab

 
  • Topic is locked indefinitely.
 

Stop using siggy, it is leaking your information

First post
Author
Jack Tronic
borkedLabs
#41 - 2014-04-10 11:41:47 UTC  |  Edited by: Jack Tronic
Jack Miton wrote:
well we used tripwire for about 3 hours before switching back to siggy, buggy or not.
tripwire... yeah... >_<


If you are saying siggy is buggy, my inbox is always open :P

Tasiv Deka wrote:
Jack Miton wrote:
well we used tripwire for about 3 hours before switching back to siggy, buggy or not.
tripwire... yeah... >_<


Literally they started toying with it while i was moving in... by time i logged they had decided it was **** and we would just deal with siggy.



evemail bugs/issues/complaints
Rek Seven
University of Caille
Gallente Federation
#42 - 2014-04-10 12:04:56 UTC
It's always risky using a third party mapping tool. It's more than likely that the corp who designed it will use it against you eventually.
Two step
Aperture Harmonics
#43 - 2014-04-10 12:45:42 UTC
Winthorp wrote:
I honestly don't know why Two Step would be a douche and post this on a public forum first? Did you even approach the siggy guy to tell them what is possible and ask that it be fixed before you spurged it over here for everyone to see?

Seems to me that you have some personal issue with this guy and you have done this spurge to ruin the in game business he has going for a lot of work invested by him regardless of peoples views on siggy (personally i don't like siggy) It just seemed a douche way to go about this Two Step.


Honestly, I didn't know who to approach about siggy. If you go to the site, it doesn't give you an email or even an eve username to get in touch with (unless I missed it).

I also checked most of the w-space groups I knew about, and when I found issues (which were with like 2 of the 10 I checked), I got in touch with the owners ASAP. Hell, no-ho.com was vulnerable for 12 hours or so.

As I said, I gave the site 36 hours or so to get fixed, and only posted here because I didn't see an alternative. I have nothing to gain or lose by siggy doing well, NOHO is currently a customer of theirs, and I don't want to see my alliancemates spied upon.

CSM 7 Secretary CSM 6 Alternate Delegate @two_step_eve on Twitter My Blog

GRIM SOAR
Deep Core Mining Inc.
Caldari State
#44 - 2014-04-10 13:15:20 UTC  |  Edited by: GRIM SOAR
Two step wrote:
Winthorp wrote:
I honestly don't know why Two Step would be a douche and post this on a public forum first? Did you even approach the siggy guy to tell them what is possible and ask that it be fixed before you spurged it over here for everyone to see?

Seems to me that you have some personal issue with this guy and you have done this spurge to ruin the in game business he has going for a lot of work invested by him regardless of peoples views on siggy (personally i don't like siggy) It just seemed a douche way to go about this Two Step.


Honestly, I didn't know who to approach about siggy. If you go to the site, it doesn't give you an email or even an eve username to get in touch with (unless I missed it).

I also checked most of the w-space groups I knew about, and when I found issues (which were with like 2 of the 10 I checked), I got in touch with the owners ASAP. Hell, no-ho.com was vulnerable for 12 hours or so.

As I said, I gave the site 36 hours or so to get fixed, and only posted here because I didn't see an alternative. I have nothing to gain or lose by siggy doing well, NOHO is currently a customer of theirs, and I don't want to see my alliancemates spied upon.


It was a douchie move. Your thread title is damaging beyond repair for those that A: don't know siggy, and B: don't have a clue what heart bleed is. You started this thread with clear intent to do damage.

Your post lacks character and supports the main stream message that standards are low for CSM members afterall.
Jack Miton
School of Applied Knowledge
Caldari State
#45 - 2014-04-10 13:20:21 UTC
Jack Tronic wrote:
evemail bugs/issues/complaints

siggy says Y790 WH is 1bil, it's not.

There is no Bob.

Stuck In Here With Me:  http://sihwm.blogspot.com.au/

Down the Pipe:  http://feeds.feedburner.com/CloakyScout

CeNSeR
Sebiestor Tribe
Minmatar Republic
#46 - 2014-04-10 13:26:42 UTC
Jack Tronic wrote:
EVEMAIL!!!! bugs/issues/complaints


Le'Mon Tichim
Hedion University
Amarr Empire
#47 - 2014-04-10 13:33:03 UTC
Tasiv Deka wrote:
Jack Miton wrote:
well we used tripwire for about 3 hours before switching back to siggy, buggy or not.
tripwire... yeah... >_<


Literally they started toying with it while i was moving in... by time i logged they had decided it was **** and we would just deal with siggy.



And made my mailbox cry as a result.

Can you hear them? They are calling to us. It is beautiful. http://thegreattichim.wordpress.com/

Ayeson
State War Academy
Caldari State
#48 - 2014-04-10 13:46:44 UTC  |  Edited by: Ayeson
Two step wrote:


Honestly, I didn't know who to approach about siggy. If you go to the site, it doesn't give you an email or even an eve username to get in touch with (unless I missed it).

I also checked most of the w-space groups I knew about, and when I found issues (which were with like 2 of the 10 I checked), I got in touch with the owners ASAP. Hell, no-ho.com was vulnerable for 12 hours or so.

As I said, I gave the site 36 hours or so to get fixed, and only posted here because I didn't see an alternative. I have nothing to gain or lose by siggy doing well, NOHO is currently a customer of theirs, and I don't want to see my alliancemates spied upon.


Siggy.borkedlabs.com

http://evewho.com/corp/borkedLabs/

It could be way easier to contact him, yes, but well....Google Fu!
Two step
Aperture Harmonics
#49 - 2014-04-10 13:46:49 UTC
GRIM SOAR wrote:


It was a douchie move. Your thread title is damaging beyond repair for those that A: don't know siggy, and B: don't have a clue what heart bleed is. You started this thread with clear intent to do damage.

Your post lacks character and supports the main stream message that standards are low for CSM members afterall.


Oh awesome, so not only do some idiots expect CSM members to adhere to some sort of magic standards, now even a year after I was on the CSM I still have to live by them? Can you please tell me what these magic standards are, nobody told me before I ran for CSM. If you look back at my forum posting history, I have always been like this, sorry if you got tricked into voting for me.

I am also so sorry I might have hurt siggy's clearly spectacular security reputation by revealing that it was in fact insecure for 3 days or so. I also am sorry I may have posted something that would have required the most cursory of google searches (or even to turn on the news) for people to learn what heartbleed was (though I have no idea why most people would care about the details, the issue was that information they thought was secure was not).

As for my intent, it was always to get siggy fixed. I don't *want* people to be able to know where people were. I don't want them to possibly be able to get other people's API keys, if people were registering for out of game access. I'm sorry if your feelings were hurt by me caring about that sort of stuff.

CSM 7 Secretary CSM 6 Alternate Delegate @two_step_eve on Twitter My Blog

Two step
Aperture Harmonics
#50 - 2014-04-10 13:47:58 UTC
Ayeson wrote:
Two step wrote:


Honestly, I didn't know who to approach about siggy. If you go to the site, it doesn't give you an email or even an eve username to get in touch with (unless I missed it).

I also checked most of the w-space groups I knew about, and when I found issues (which were with like 2 of the 10 I checked), I got in touch with the owners ASAP. Hell, no-ho.com was vulnerable for 12 hours or so.

As I said, I gave the site 36 hours or so to get fixed, and only posted here because I didn't see an alternative. I have nothing to gain or lose by siggy doing well, NOHO is currently a customer of theirs, and I don't want to see my alliancemates spied upon.


Siggy.borkedlabs.com

http://evewho.com/corp/borkedLabs/

Google fu!


Clearly you are a smarter man than I. I went to www.borkedlabs.com in the hopes that I would find something and just got an error.

CSM 7 Secretary CSM 6 Alternate Delegate @two_step_eve on Twitter My Blog

Ayeson
State War Academy
Caldari State
#51 - 2014-04-10 13:48:31 UTC  |  Edited by: Ayeson
Two step wrote:


As for my intent, it was always to get siggy fixed. I don't *want* people to be able to know where people were. I don't want them to possibly be able to get other people's API keys, if people were registering for out of game access. I'm sorry if your feelings were hurt by me caring about that sort of stuff.


Could you please stop caring and just adhere to the magical set of rules and standards all Ex-CSM members must adhere to? kthx

Edit: Yeah the default webpage is just an apache landing page, you should probably get on that JACK.

MAKE IT EASIER FOR US TO ***** ***** AT YOU, LIKE WITH A CONTACT FORM OR SOMETHING

EDIT2: The content filter on the EVEO forums still skips the second curse word
Hidden Fremen
Lazerhawks
L A Z E R H A W K S
#52 - 2014-04-10 14:20:26 UTC  |  Edited by: Hidden Fremen
Jack Tronic
borkedLabs
#53 - 2014-04-10 14:22:33 UTC  |  Edited by: Jack Tronic
Jack Miton wrote:
Jack Tronic wrote:
evemail bugs/issues/complaints

siggy says Y790 WH is 1bil, it's not.


Fixed.

Quote:

Edit: Yeah the default webpage is just an apache landing page, you should probably get on that JACK.


That default domain landing page is on a different server. I have 4 different servers under the domain for different purposes.
Ayeson
State War Academy
Caldari State
#54 - 2014-04-10 14:51:40 UTC
Jack Tronic wrote:

That default domain landing page is on a different server. I have 4 different servers under the domain for different purposes.


Why dont you just put a "contact us" page on the siggy.borkedlabs.com site then?
Two step
Aperture Harmonics
#55 - 2014-04-10 16:33:52 UTC
Ayeson wrote:
Jack Tronic wrote:

That default domain landing page is on a different server. I have 4 different servers under the domain for different purposes.


Why dont you just put a "contact us" page on the siggy.borkedlabs.com site then?


Or even just your name/email, I would totally have reached out that way first!

CSM 7 Secretary CSM 6 Alternate Delegate @two_step_eve on Twitter My Blog

Jack Tronic
borkedLabs
#56 - 2014-04-10 17:11:06 UTC  |  Edited by: Jack Tronic
Two step wrote:
Ayeson wrote:
Jack Tronic wrote:

That default domain landing page is on a different server. I have 4 different servers under the domain for different purposes.


Why dont you just put a "contact us" page on the siggy.borkedlabs.com site then?


Or even just your name/email, I would totally have reached out that way first!


Well there's that but at the same time responsible disclosure doesn't involve bragging about OMG LOOK AT WHO I AM SPYING ON AND WHERE :P

But yea the public facing side is dated and past its age, I guess its time to fix that.
Winthorp
#57 - 2014-04-10 23:05:45 UTC  |  Edited by: Winthorp
Two step wrote:
Winthorp wrote:
I honestly don't know why Two Step would be a douche and post this on a public forum first? Did you even approach the siggy guy to tell them what is possible and ask that it be fixed before you spurged it over here for everyone to see?

Seems to me that you have some personal issue with this guy and you have done this spurge to ruin the in game business he has going for a lot of work invested by him regardless of peoples views on siggy (personally i don't like siggy) It just seemed a douche way to go about this Two Step.


Honestly, I didn't know who to approach about siggy. If you go to the site, it doesn't give you an email or even an eve username to get in touch with (unless I missed it).

I also checked most of the w-space groups I knew about, and when I found issues (which were with like 2 of the 10 I checked), I got in touch with the owners ASAP. Hell, no-ho.com was vulnerable for 12 hours or so.

As I said, I gave the site 36 hours or so to get fixed, and only posted here because I didn't see an alternative. I have nothing to gain or lose by siggy doing well, NOHO is currently a customer of theirs, and I don't want to see my alliancemates spied upon.



TBH that is a bullshit reason, you honestly didn't know bahahaha. Every man and his dog knows who runs siggy, if you didn't want to contact his main then on siggy itself for a little effort (And you clearly went to effort to investigate the hack) then you would have been able to contact the siggy cover alt.

Its still a douche move you made and you know it.
Sith1s Spectre
Imperial Academy
Amarr Empire
#58 - 2014-04-10 23:13:37 UTC
Out of curiosity. Isn't hacking a website in the states a federal offence?

Personally I don't care but if it is I sure wouldn't be publicly admitting to it.

Resident forum troll and fashion consultant

Camper101
State War Academy
Caldari State
#59 - 2014-04-11 08:56:24 UTC
Sith1s Spectre wrote:
Out of curiosity. Isn't hacking a website in the states a federal offence?

Personally I don't care but if it is I sure wouldn't be publicly admitting to it.



Now, if you would actually hack the site and not just listen to what it broadcasts to everyone, maybe, yes.

On the other hand: i'd rather thank the guys than scaring them off. Because those that use the bug in a malicious way wont tell you about it. and do things to you. Nasty things. Without ppl looking for holes in those protocols not a single security gap would have been detected and all your *insertrandomwebmailservice here* *insert random MMO here* passwords would be available for everyone that has a clue freely.

But back to topic, no he didn't hack, he just read what was broadcasted anyway :P

2013.03.01 13:30:58 notify For participating in the General Discussion Forum Section your trustworthiness has been adjusted by -2.5000.

My name is Hans. The "L" stands for danger.

Meytal
Doomheim
#60 - 2014-04-11 12:03:24 UTC
Two step wrote:
If you look back at my forum posting history, I have always been like this, sorry if you got tricked into voting for me.

Confirming, he was like this while CSM as well.