| Post/Author/DateTime | Post |
|---|---|
| #1gregt_314Aug 12, 2009 0:42:44 | By way of community feedback, because I'm a little angry and this is far and away the most appropriate place to discuss it: I made a post today that there was a legitimate reason to delete - not because it was offensive in any way, but because it mentioned the existence in a very, very general way of a way to subvert Wizards' intellectual property. It was on the level of, "Sometimes illegal material is available through peer-to-peer sharing applications." Wizards are within their right to delete such a post, even if it is to a large extent closing the door after the horses have bolted. What I'm a little upset about is getting an email about it warning me that I had committed "illegal activities" under the Code of Conduct. For these reasons: (1) The Code of Conduct isn't a law and no violation of it can be "illegal". I don't appreciate being called a criminal because of a forum post. I suspect the email intended to say I'd been discussing potentially illegal activities but that's not how the email was phrased. (2) If I point out a flaw in Wizards' security in a polite way - and bear in mind I didn't provide any details of how to exploit it, and in fact am not precisely clear on that myself - I'm happy to receive a, "Thanks for pointing that out but we'd prefer it not to be on our boards", but a threatening email is out of line. Next time when I notice a security hole I'm tempted to keep quiet and let Wizards find out when less vocal and law-abiding people make use of it. (3) The post was humorous. There's a difference between not finding it funny, and not acknowledging that it was intended to be funny. Anyway, that's how I feel. I'd prefer to not worry about whether polite, well-intentioned posts made on these forums are going to result in legal action. The email, by the way, also contained an invitation to fill out a questionnaire on how I'd been handled by customer service. I filled out that questionnaire, and it was obvious that it was intended for people who'd made an enquiry of customer service, not people who'd received threatening unilateral form letters. Anyway - thanks. |
| #2WebsterAug 12, 2009 1:14:34 | You're not being called a criminal. "Illegal activities" warning includes but not limited to discussion of and/or promotion of illegal activities. The warnings are to give you a heads up not do do it again. And you acknowledged that it was delete worthy- so why post it? If you find such a security loophole, it's best to just send it to customer service rather than post it. "Hey! Here's an exploit for everyone to see so they can exploit it before it's locked up!" isn't really helpful. Doing so behind the scenes is. ;) |
| #3gregt_314Aug 12, 2009 1:47:11 | You're not being called a criminal. "Illegal activities" warning includes but not limited to discussion of and/or promotion of illegal activities. No, I get that that was the intention. I'm saying that wasn't how the email was phrased. The phrasing of the email was that the post had been deleted because the post itself was an illegal activity. It's probably not what they meant to say, but that doesn't change the fact they said it, in a formal email couched in legal language bearing Wizards letterhead, sent to my personal email address. To be clear - I'm not upset that the post was deleted. It was, like, one line. I've got plenty more words where that came from. I'm upset about the tone and content of the email I received letting me know the post had been deleted. The "fill in the blanks" form letter sent out by the ORC (or whoever) in this case produced a result that was threatening and offensive far out of proportion to the content of the post itself; as a method of communicating with customers it was neither accurate nor polite. |
| #4misterfido_dupAug 12, 2009 3:00:25 | If you find such a security loophole, it's best to just send it to customer service rather than post it. "Hey! Here's an exploit for everyone to see so they can exploit it before it's locked up!" isn't really helpful. Doing so behind the scenes is.;) I dunno about THAT. In my experience--and surely other people's--politely and privately informing a company of a bug or security problem gets attention at the Speed of Bureaucracy. That is, as soon as it moves up the tech ladder to someone who cares, then up to someone who can order someone else who knows how to fix it to add it to their to-do list of things to be fixed... it will eventually be put on the board for review for fixing. And of course, it has a strong, strong chance of getting lost and forgotten. If you post exploits in a public place, you get response times at the Speed of Angry Bureaucracy. That is to say... Take video games by Valve. Their philosophy is "Release first, patch later" and it generally keeps their fans happy. But sometimes (or, rather, every week) there will be a new exploit on the market. One waiting to be fixed in Team Fortress 2 at the moment, is you can install a client-side hack that makes every shot you fire an automatic critical. Now, let us review the two approaches to informing the company: A) Bug complaints, filed through official (read: clogged) channels from an in-game menu item. It gets passed from one team to another, moving up and down the ladder like an 8-bit Mario fighting Donkey Kong. This is the approach currently being taken, and it's taking forever. Several patches have gone by without it being fixed. B) Open discussion. While against the policies of their boards, suppose dozens of members were to go on their forums and openly discuss how this hack is done, and what Valve should do to fix it. Sites with the hack client are linked to. People who have never heard of this cheat become curious and look it up even without links, and download it. Soon, every server in the game is filled with crit-rockets and crit-fire. Holy Hell. And the forums... the forums become bogged down with complaint threads. The bug reporting system is equally clogged with complaints. There is no dev who even glances at the community who doesn't have this hack's haters and lovers burnt into his retinas. Now, I don't disagree that promoting illegal activity is bad, and what's more, since this is a company-operated board, they're within their rights to remove material that harms the company. BUT. Discussion of security loopholes leads to exploitation... and nothing gets a fix for a critical problem moved to the correct person on the corporate ladder FASTER than a security exploit harming the company's bottom line. Method A does not get this response time. Method B does. I forsee agreements on both sides of this issue, consumer and producer, that major company-harming problems are addressed quickly. The only thing we fail to see eye-to-eye on is the cost. To the consumer, discussion of illegal activities, whether a game hack or a method of stealing PDFs, gets a serious problem fixed ASAP, which makes them happy. To a company, discussion of those activities means they have to spend oodles of time and money that could've been spent elsewhere fixing problems that were more important until the exploit became public. To the consumer, we see openly reporting illegal behavior so that others can repeat it and put pressure on the company, we see that as the most efficient means of getting bugs fixed possible, because it gets results, FAST. To the company, they see those reports as the least efficient means of getting bugs fixed possible, because it costs so much money and time to get it done QUICKLY. This is all just my two coppers. I just wanted to provide a bit of my own insight, since Webster implies reporting problems to customer service is best when, historically, it's not; and maybe some insight to GregT, who might realize that even the mention of illegal methods of stealing PDFs invokes a knee-jerk response to delete, delete, delete, so that the company can spend its resources in more important places. Remember, Wizards is under a hiring freeze (last I knew) and has limited resources. Let's not push them into working on the PDF issue any more than is necessary, when they could be working on so much else. |
| #5tiwaztyrsfistAug 12, 2009 11:32:49 | As anyone who reads /. can tell you, pointing out a security flaw to a large compaky has a roughly 80% chance to get you arrested for a whole slew of randomly selected computer crimes. |
| #6misterfido_dupAug 12, 2009 12:06:04 | Oh, well, yeah. But they can do that even if you report it privately. So lets leave option C, where you pretend you don't know about a security loophole because sometimes companies are major ****s who will sue you just for the sake of getting your money, even if you're helping them. |
| #7RUMPLESTIXAug 12, 2009 16:08:36 | Oh, well, yeah. But they can do that even if you report it privately. So lets leave option C, where you pretend you don't know about a security loophole because sometimes companies are major ****s who will sue you just for the sake of getting your money, even if you're helping them. They can do a lot of things. However if you wish to compare the chances of getting arrested for quietly reporting to a company a security flaw that it has and compare it to the chance of getting arrested for publicly reporting such a flaw I will guarantee that the former chance is infinitesimal when compared to the latter. Companies will not sue (I won't say never just because...) an individual who helps just to get their money. Litigation costs money and it will cost a company far more to pay its lawyers than it can hope to get in return unless there was an enormous amount of high dollar illegal activity committed by the individual. The reason companies often settle out of court on cases they could win is twofold. First, it will not be cost efficient for tem and thus a bad business practice. Second is that it can backfire with the public and thus be bad for business. Companies rarely go to those extremes without having a great deal of evidence on their side and a lot of money at stake. If a problem is widespread and the company has ample evidence then it might make an example of someone to stop a larger problem. However, in that case, they are not after the individual's money but they are after stopping/reducing a larger scale illegal activity. |
| #8DuskweaverAug 14, 2009 1:50:14 | a roughly 80% chance to get you arrested for a whole slew of randomly selected computer crimes. GregT_314 should just be glad WotC isn't run by the Pentagon... ;) |