I will answer the other people that are concerned about this issue.
RBerenguel wrote:Thanks for posting illluck. I was thinking about becoming a founder of kaya.gs, it looks an interesting project. I'd rather not, even more after reading yesterday the PR onslaught on the avenger controller PR-guy.
Security by obscurity in very-late-2011? Seriously? And what do we do when all our emails (possibly also Facebook, Twitter, paypal and more information) are compromised because the server was broken because "you knew about the SSH patch but thought it was not that important/known"?
First of all RBerenguel, take let's take a step back and look at the situation as a whole. Kaya.gs Alpha had no security breach because it had no sensitive information. How things were handle was known for all users right from the start, because it was of public domain. illuck's post doesnt not reveal any information founders didnt know right from the start, which is why people that considered their email sensitive, sent apersonal email to me, instead of putting it in the server.
There is no security issue in kaya because we do NOT store passwords and certainly not any other kind of sensitive information. That is not how a basic security system works.
If we were to handle such, we would take the proper cautionary precautions as i did as soon as i saw fit that a user had intentions of posing other users for his own content, which is what happened.
cata wrote:I don't give a crap about the security of the alpha test (although it's sort of bizarre that Kaya wouldn't just email out registration links where you can set your password and be done with it) nor do I really care what anyone says in a chatroom, but when I read this PM excerpt
"I dont really take your post seriously, but i know other people might. Just in case that you really intended to put ur 2 cents and not just negatively blabbering about something, i must say that the greatest "security concern" to ever happen at Kaya.gs was you, by publicizing things that might want other users try to break things up, or panic."
it made me wish I could withdraw the donation I made earlier this year. Just some feedback on customer relations.
I am sorry that you perceive something so negative about that private message i sent to Illuck. It might be lost in translation ,but even re-reading it after a good night sleep, the point still stands. He made an aggressive post, that showed me he had intentions of impersonating other users, which is why i promptly (in the next 2 hours) i put up the passwords, which were already implemented well from before, but i needed to be able to send them to as most founders that i could.
Regarding the chat in the server, it is taken quite out of context, as several founders know i even jokingly call dp such when something has to be done on the design/board functionality.
I am sorry i have made you or anyone else that supports this project upset at this event. I will be more carefuly with my wording in the future.
Just take into account the facts, as how someone made a very agressive post in a very bad tone:
-I responded both publicly (explaining and determining a course of action) in a polite manner,
-I responded privately (telling him what is the proper procedure if security concerns are really legitimate).
-I reacted to the situation by promptly fixing it.
-Right from the appearence of the post, i told all founders that were in the server and was completely open about the issue, the process of the solution and the outcome as they were being developed. Let me add that this "illuck's issue" was discussed and talked over many times inside the server with the founders and had founderst shown or expressed any concern from it, i would have finished it before.
The only reason why i delayed it was the bureacracy of matching emails with the paypal donations.
I have no intentions of responding to Illuck's posts as they are obviously meant to be inflammatory, which is why my private message was sterile. He has done things with ill intentions , including publicizing private messages and impersonating a founder. I also understand that the standard for me is higher than him, as i have more responsibilities, which is why i repeat, im sorry of this dissapointment for you (or any other founder that might feel the same) and i will be more careful in the future in the way i communicate with hostile and ill-intended users.
I stand by the message now public message, that illucks concerns are not shared by my own. But as it is usual in human behaviour, if someone says its serious, others can believe it even though its not. I was not demeaning the concern of adding passwords, i was stating that the message he originally posted made the "problem" much much worse, by showing that at least one user(himself) had intentions to log in as another founder, and inciting others to do so by providing the means comfortable through links to all the informatino.
Maybe i perceive a tone of agressiveness from this posts that other users don't, but they are certainly meant for that.
I did learn a lesson from this, and that holding this project raises my profile and some people can be tempted into damaging my image or worse, the projects image. I promess i will make an effort to keep such opportunities to the minimum.
I hope you feel better about this whole matter after reading this post, cata.
daal wrote:Illuck made nothing public that wasn't already obvious, and the tone of Gabriel's responses is extremely disappointing to this "founder" and probably more damaging to kaya.gs than anything anyone else could say.
Except he has a name i dont know, or he really didnt want me to know he was a founder, he isn't one. illuck has no relation whatsoever to the Kaya.gs project ,other than his curiosity. He is not a customer or a user, he is just someone that read the blog and blew public information out of proportion.
You can talk to any founder in the server and ask them how i have been treating them, and i assure you they will tell you that i've done everything in my power to be of assistance.
Just in case im totally wrong about him, i invite him to continue a private conversation, were all the details can be discussed and ironed out, and later on we can post a public message in mutual agreement with our conclusions of the whole ordeal.