Welcome to Gaia! :: View User's Journal | Gaia Journals

 
 

View User's Journal

Report This Entry Subscribe to this Journal
Less than daily ramblings from a Gaia developer


carbonphyber
Community Member
avatar
18 comments
Hackers and scammers: your Gaia days are numbered
I'm switching gears starting today. Instead of building more new features/upgrades to user features, I'll be building better tools to fix scams and hacks.

I will still be processing Bug Reports, but my priority will be to fix and upgrade the Admin/Mod tools. We will be empowering Admins/Mods to do their job more effectively -- which means hacks and scams will be caught earlier and removed from the site quicker.

Side effects of addressing this will be better privacy and permissions enforcement by all parts of the site.


Your thoughts?


[center:b7fee9207a][img:b7fee9207a]http://i453.photobucket.com/albums/qq256/carbonphyber/searchbar.png[/img:b7fee9207a][/center:b7fee9207a]




User Comments: [18]
Insanity_Is_Freedom
Community Member





Wed May 12, 2010 @ 07:48am


Don't hurt me!!! >.>;;

Kidding. I'm a law abiding, GC spending, hoarding Gaian. Or something.


I digress.

I feel that most of the scams occur in Towns, by which people are like CLICK HERE LAWL. Or w/e.

But man, you better put a ban-hammer item on your avatar. You better.


Lady Kayura
Community Member





Wed May 12, 2010 @ 09:50am


Glad to hear that you'll be working on something like this and scams/hacks will be removed faster. I'm not dumb enough to give my PW out but hacking does worry me. Just need to accidentally go to the wrong website to get a keylogger. I like the idea of better privacy and permissions. I can't help but to wonder if you'll be addressing the ignore feature at all. Wish you guys would consider a revamp of the trading system and incorporate a pin number, where you click numbers (have it be 4 numbers) and have the images of the numbers move and make it optional. And make the PIN number also be required for gifting. I know, I know. If someone's dumb enough to give their PW, they'll give their PIN but if someone is legitimately hacked, then this may help. Keylogger? This may help.


Nyadriel
Community Member





Wed May 12, 2010 @ 09:53am


I dunno. I am a little...

I mean, you need to pay attention to the fact that some of us are on a fast computer and fast internet. I was once accused of botting simply because an item was bought the very second I put it in my shop and had sold half my Sealed letters I just bought that morning. It took a Dev to check the records and see that I wasnt botting at all.

So in all this, you need to figure something out to help your tools distingush the difference between botters and those of us who are on a speed of warp 9. Of course, I know how impossible that might be.

As for the scams and hacks, does this refer to the reports?
I hope that what you will be doing will not hinder the innocent in any case. Including putting in any pin numbers anywhere. I dont see how that will work.

Also Towns and Rallies really need to be dealt with where scams and hacks are concerned. Seriously needs work there!


Jayce Reinhardt
Community Member





Wed May 12, 2010 @ 02:31pm


The majority of scams I see are the people pretending to be staff, claiming someone was accused of something and asking for the persons password to "check things out"

People seem to make threads "warning" us of them in the GCD. I though you couldn't type in the password anymore. confused


Mindset
Community Member





Wed May 12, 2010 @ 08:26pm


Excellent news. I look forward to the mod tools upgrades.

Would this include adding a report feature to user profile comments? It's honestly surprising that the only way to deal with a TOS violation in one of those is to contact a mod directly. They're frequently used for the image/password popup scam and the "Beta Daily Chance" scam, especially on Featured Users and NPC profiles.

Another useful feature would be a revamp of the trading system -- which is probably outside of the "mod tools" range, but it does really need some changes. The only way to see a traded item name is on hover -- wouldn't it be better to be displayed next to the item itself? You wouldn't need sparkles to distinguish a corsage from a Winter Rose if "Winter Rose" were printed right there.

Anyway, mods would be able to give you better feedback on these upgrades -- I hope you're in touch with them to see what they really have been wanting. smile


armadillodreamer
Community Member





Wed May 12, 2010 @ 10:04pm


Awesome! See if you can block those pop-ups that ask for a users for their IDs and passwords too, if you have time.


Valentine
Community Member





Thu May 13, 2010 @ 06:09pm


Good luck! Sounds like a worthy endeavor.

... I think I'll miss your features/upgrades, though. sweatdrop


Sand Dancer Shaka
Community Member





Thu May 13, 2010 @ 08:49pm


Giving Mods/Admin empowerment is a really good idea, it should help speed up processing of reports as well as be better for morale ^^


carbonphyber
Community Member





Wed May 19, 2010 @ 01:04am


Thanks for the feedback!

Re: other features:
I will not stop working on other features. In fact, I will be building infrastructure to allow other Devs to use better code for their new user-facing apps.

Re: "PIN" codes:
Panagrammic has actually toyed with the idea of texting you (the account owner) a new SMS message every day. This code would be required in addition to your username+password before you could transact (trade, vend, gift, buy, etc) items. We might see it in Labs in a few months.

Re: Towns+Rally
Two developers are working on securing Towns and Rally. Instead of trying to plug hundreds of small holes in the Dam, they are building a bigger, better dam downstream.

My Hope is to be able to give Mods awesome tools so they are able to identify and banish new styles of scams all at once, rather than removing one scam/link at a time. "Batching" Moderator actions seems more logical to me. A side-effect of this would be that Mods would be able to spend more time working "botting" issues. We wouldn't need to ban as many accounts -- we could simply disable trading passes for a few hours until the account is investigated.

Also, I'd like to be able to get some tools to allow Mods to constantly monitor high-traffic pages (such as profile comments on the Featured Avi profile).

Also, any place on the site should be reportable. We do have problems with content that is unreportable because we don't have a "report" button.


David2074
Community Member





Fri May 21, 2010 @ 05:33am


It sounds like you are spread thin between the bug fixes and the scam/hack tools but I like the ideas you mentioned and look forward to seeing the effects of the improvements.


Lady Kayura
Community Member





Mon May 31, 2010 @ 10:54pm


Quote:
Re: "PIN" codes:
Panagrammic has actually toyed with the idea of texting you (the account owner) a new SMS message every day. This code would be required in addition to your username+password before you could transact (trade, vend, gift, buy, etc) items. We might see it in Labs in a few months.

My Hope is to be able to give Mods awesome tools so they are able to identify and banish new styles of scams all at once, rather than removing one scam/link at a time. "Batching" Moderator actions seems more logical to me. A side-effect of this would be that Mods would be able to spend more time working "botting" issues. We wouldn't need to ban as many accounts -- we could simply disable trading passes for a few hours until the account is investigated.

Also, I'd like to be able to get some tools to allow Mods to constantly monitor high-traffic pages (such as profile comments on the Featured Avi profile).

Also, any place on the site should be reportable. We do have problems with content that is unreportable because we don't have a "report" button.



PIN codes.. wow, text message. I absolutely LOVE this idea. I hope when it is implemented, perhaps we can pick what time we receive the message so it isn't being delivered in the middle of the night?

Yay, report button for comments. I can't wait to see this! <3 I hope it affects all profiles and not just the featured avatar's profile. Spam and trolling can happen on standard profiles too.


tiranaki
Community Member





Mon May 31, 2010 @ 11:13pm


Just wanted to say thank you <3

as someone that works with hacks, scams and botting, THANK YOU.


Quixotic Quidam
Community Member





Tue Jun 08, 2010 @ 06:57am


I think these are brilliant ideas, thank you for addressing the issues.


OHAI Im Jordan
Community Member





Sun Jun 27, 2010 @ 06:48am


My friend has recently been hacked by a link on her profile. I think you should build a link monitor that detects malicious, or phishing sites that can harm your computer, or your gaia account.


Chocobo Princess
Global Moderator





Wed Jul 07, 2010 @ 01:36am


"Re: "PIN" codes:
Panagrammic has actually toyed with the idea of texting you (the account owner) a new SMS message every day. This code would be required in addition to your username+password before you could transact (trade, vend, gift, buy, etc) items. We might see it in Labs in a few months. "

I would rather not see a PIN added for Gaia trades and marketplace transactions. How many agents would be standing by on Gaia's end to resend/replace/redo the PINs 24 hours a day for Gaians who accidentally deleted the message/lost the phone and got a new one with a new number (many but not all of which requests are likely to be hack attempts)/got grounded and are not allowed to use a cellphone? sweatdrop It just doesn't seem like an efficient use of your workhours to me; I'd rather have the team continue to work on bug fixes and new events.

Also, I do not have a cellphone, so would I not be able to be a fully-functional Gaian after this update? redface

Hooray for more efficient tools for the moderators~!
blaugh


GrafinGothicwar
Community Member





Tue Jul 27, 2010 @ 08:40am


THANK YOU! I still consider myself new to Gaia, but have been amazed at how many scams I have already run into. It is good to know that the powers that be (developers like you) have noticed it as well and are working on the situation.


oEnrique
Community Member





Tue Jan 04, 2011 @ 11:13pm


XD their are other ways hackers can get are passwords this was a fail :l


jellykans
Community Member





Wed Apr 06, 2011 @ 08:58pm


I made a typo last week and really got upset at the result. (I tested it until I reproduced the effect.)

I googled gaiaonline c (omitting the .) and up popped a bunch of sites called "gaia cheats."

It never occurred to me to report it to gaia, but I guess you folks know about it. I told a friend (who knows developers, not like me), figured he would know who to report it to, if it needed to be done. But it just made me angry. Why be destructive of a good thing? Somebody had 'Hackers not crackers' in their sig and I am all for that. I remember when hacker meant someone who loves elegant code...

Thank you for working on gaia. It's two-edged. You get really wonderful work, but you also get a lot of flak - so - duck when it's needful!


User Comments: [18]
 
 
Manage Your Items
Other Stuff
Get GCash
Offers
Get Items
More Items
Where Everyone Hangs Out
Other Community Areas
Virtual Spaces
Fun Stuff
Gaia's Games
Mini-Games
Play with GCash
Play with Platinum