2021-05-24 18:44:30

How you guys know that they responded? I don’t see any news about this.

Best regards: Marco

2021-05-24 18:48:23

Please reread the thread. It states very clearly in one of Carter's posts and one of Jack's posts that the webmasters responded.

Check out my Manamon text walkthrough at the following link:
https://www.dropbox.com/s/z8ls3rc3f4mkb … n.txt?dl=1

2021-05-24 20:32:29

@52 Yup
@51 They responded through email, so you wouldn't see it here.

-----
Matthew's Horse Needs Your Support!
Discord: misterkrabs69

2021-05-24 22:09:52

Very painful someone didn't read the threat..

You ain't done nothin' if you ain't been cancelled
_____
I'm working on a playthrough series of the space 4X game Aurora4x. Find it here

2021-05-25 02:11:38

Oh, i noticed the post now, as i had more time to read the thread.

Best regards: Marco

2021-05-25 22:45:33

@56
wrong thread I think.

My Blog
Twitter: @ajhicks1992

2021-05-26 01:09:53

moderation:
What was #56 has been removed as it was entirely off-topic. We aren't typically in the habit of doing this, but see #2 for a full explanation.

2021-05-26 02:02:16

Well, I'll try posting again, since apparently the forum's not hating me so much right now.

Adding this to the email is broken pile, but I've got a weird one. So everyone's saying the email is broken. That's not what I'm saying. I know the email's broken with the error 400. However, the email still, at least here, seems to go through anyhow even wit the error code given once you submit the email. I'm not 100% sure if that is entirely a site issue or email server issue, or both. I just figured I'd add it to the issues list since apparently, at least for me, the emails aren't entirely broken and refuse to send once submit is hit

Warning: Grumpy post above
Also on Linux natively

Jace's EA PGA Tour guide for blind golfers

2021-05-26 17:38:00

Just had a quick question. At the bottom of the Forum, there's this thing that I thought usually said 4 official extensions. Now it has the number 5. Am I crazy, or did something change?

-----
Matthew's Horse Needs Your Support!
Discord: misterkrabs69

2021-05-26 18:33:52

Nope, it changed. No idea why. Maybe the webmasters installed something.

2021-05-26 19:12:02

One more on the issues pile. I've raised this before but never been able to reproduce it.

Essentially, if you log in with two topics open, say this one and the site FAQ for example, and you log in. You'd expect to be taken back here because that's where you logged in from.

NHope. Both tabs will be the site FAQ in this example. Which is very very infuriating when you're reading two threads and go to reply to one, then the other

Warning: Grumpy post above
Also on Linux natively

Jace's EA PGA Tour guide for blind golfers

2021-06-03 00:56:07

Sorry to cast Summon Bones on this topic, but is there any news about what's going on here?

2021-06-03 12:44:16

It's ironic that I was just leaving this thread and about to check the dev room when this happened, so now I'm back big_smile

Error 520Ray ID: 65984ff38eb90f22 •2021-06-03 10:42:00 UTC
Web server is returning an unknown error
You
Browser
Working
Dallas
Cloudflare
Working
forum.audiogames.net
Host
Error
What happened?
There is an unknown connection issue between Cloudflare and the origin web server. As a result, the web page can not be displayed.
What can I do?
If you are a visitor of this website:
Please try again in a few minutes.
If you are the owner of this website:
There is an issue between Cloudflare's cache and your origin web server. Cloudflare monitors for these errors and automatically investigates the cause. To help support the investigation, you can pull the corresponding error log from your web server and submit it our support team. Please include the Ray ID (which is at the bottom of this error page). Additional troubleshooting resources.
Cloudflare Ray ID: 65984ff38eb90f22 • Your IP: 2603:8081:6501:a032:e875:7eca:5519:12d5 • Performance & security by Cloudflare

2021-06-03 19:04:47

@63: Well, that really helps a lot! CF is indicating that the forum threw an error, but they don't know how to handle it and won't tell us what it is!

2021-06-03 19:12:10

I've seen something like that before.

Facts with Tom MacDonald, Adam Calhoun, and Dax
End racism
End division
Become united

2021-06-04 00:58:50

I think we shouldn't attempt to rush it for now. Give it a month or so. They already said they're in contact with them, so all we can do is hope and wait

You ain't done nothin' if you ain't been cancelled
_____
I'm working on a playthrough series of the space 4X game Aurora4x. Find it here

2021-06-04 10:58:34

The errors here don't bother me personally. I just thought I should report the error in case it gave additional info.

2021-06-25 23:12:22

So I'm curious.  It's been something like a month.  What's the status of this?

My Blog
Twitter: @ajhicks1992

2021-06-28 02:48:11

I'm going to guess nothing since this topic has remained quiet from the mods at least since May 25. So about a month and 2 days.

"On two occasions I have been asked [by members of Parliament!]: 'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out ?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question."    — Charles Babbage.
My Github

2021-06-28 06:03:02

not trying to be negitive, but i'm not serprised, and add this to the problems with non existing accounts, that is kinda fixed but still, a password breach or exploit letting someone in to those accounts, and this, it seems at though we gotta jump ship before this all falls down, run that db scraper and get everything downloaded, then we leave

i am a system, i have headmates, and that is my life, and my discord is rings2006wilson#8609

2021-06-28 20:29:56

Thanks for the amusement @70, but the reality fortunately isn't nearly so melodramatic.

We're still in talks with the hosts. This process has been slowed a bit while they work to maneuver exam season, but mostly because in a twist of annoying irony they've had to defer to their own hosts which were apparently something of a struggle to get a hold of. We have a response now though, and a meeting is planned this week to review it in more detail.

There is no reason to believe that we've been victim of a data breach of any kind.
We're looking into it, and if this changes you'll of course be made aware, but right now it's a pretty strong hunch telling me that unsecure/repeatedly used passwords are the real culprit. Even if it would happen that someone manages to pwn the server and gain access to it's contents before us, so far as I've been able to figure out, passwords are SHA1 hashed with a random salt--which is at least something.

SHA1 was reasonable back in 2005, but has since been prone to multiple collision attacks in the wild and as such is far from safe now. It is my hope to change this for new accounts and password resets asap, though the list is ever growing and I'm typically the guy begging teams to avoid PHP like the plague. Oh well. Point is, you aren't dealing with opening notepad on chars/pass.usr or something.

At any rate, progress is being made. A lot more should be known later this week.

2021-06-28 21:29:45

and thats good, and i agree if theirs no sines of it, its not a thing, but still

i am a system, i have headmates, and that is my life, and my discord is rings2006wilson#8609

2021-06-29 06:32:15

Well that's something, 71. Glad to hear things are progressing, if slowly.

"On two occasions I have been asked [by members of Parliament!]: 'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out ?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question."    — Charles Babbage.
My Github

2021-06-29 18:50:39

@71 Correct. It does use a salt. Maybe I'm misremembering here but back when I had BPC I had created a system to allow TDV accounts to log in to the forum. I think the passwords were double hashed, so it was something like sha256(sha256(...) with salt). So I doubt passwords themselves have been compromised. This was using PunBB and not Pan though.

2021-06-30 01:48:54

@74, hashing a password multiple times doesn't bring any actual security benefit though. It does if you use it in the context of a hashing algorithm that preserves the entropy of the has (e.g. your designing your own hashing algorithm) but its not secure to do sha256(sha256(password)) or variations thereof. See this Stack Overflow post for explanations.

"On two occasions I have been asked [by members of Parliament!]: 'Pray, Mr. Babbage, if you put into the machine wrong figures, will the right answers come out ?' I am not able rightly to apprehend the kind of confusion of ideas that could provoke such a question."    — Charles Babbage.
My Github