forum

RIP strager

posted
Total Posts
37
show more
Ph0X

awp wrote:

He got banned for exploiting people's stupidity?

Kinda feels like banning Darwin, doesn't it?
I totally knew what I was stepping into :|
I was NOT exploited ;_;
nardii
fucking ballsack
Topic Starter
Pokebis
RIP Failed_Ph0X
;-;
mm201
I wasn't there but tinyurl I presume? Easy enough to direct someone--even someone who knows what they're doing--to open a link.

"Security activism" only makes sense if you've given the author of the insecure software fair warning.
Ph0X

MetalMario201 wrote:

I wasn't there but tinyurl I presume? Easy enough to direct someone--even someone who knows what they're doing--to open a link.

"Security activism" only makes sense if you've given the author of the insecure software fair warning.
I have tinyurl preview cookie enabled, but no.
It was a simple osu link. It was disguised as a normal link profile link, but I noticed it was longer.
I still pressed it because I trusted strager and tbh, didn't really give a shit. peppy did get mad at strager but I was laughing the whole time on vent even though he fucked up my name. I knew peppy would fix it anyways so I wasn't worried or anything.

I think strager actually helped by figuring this out because some other random guy abused it even more.
Mashley
Actually, mine was a link to strager's site.
peppy
I don't have a problem with people searching for security holes. I am grateful that he found this problem. I do not approve of the fact that he caused four username changes, then a fifth after i was working on fixing it, wasting my time and causing unnecessary commotion. That is just total asshattery and deserves no place in this community.

I also don't believe this needs further discussion as you guys seem to fail at keeping a conversation of this nature from going down the drain. Not going to lock, but just saying.

It is not the first instance strager has displayed negative behaviour. While he has contributed good to the community as well, this nullifies any right he has to hang around here.
Ephemeral
strager never did know when to stop.

This was inevitable, really.
bagnz0r

peppy wrote:

I don't have a problem with people searching for security holes. I am grateful that he found this problem. I do not approve of the fact that he caused four username changes, then a fifth after i was working on fixing it, wasting my time and causing unnecessary commotion. That is just total asshattery and deserves no place in this community.

I also don't believe this needs further discussion as you guys seem to fail at keeping a conversation of this nature from going down the drain. Not going to lock, but just saying.

It is not the first instance strager has displayed negative behaviour. While he has contributed good to the community as well, this nullifies any right he has to hang around here.
Well, for first time ever I have to agree with peppy here.
That wasn't really white hat behavior, strager.
Nakata Yuji
I don't know if this is out of place, but did he give a link that tricked people into changing their names? What exactly happened..?
Vanmonky

Nakata Yuji wrote:

I don't know if this is out of place, but did he give a link that tricked people into changing their names? What exactly happened..?
Topic Starter
Pokebis

peppy wrote:

I don't have a problem with people searching for security holes. I am grateful that he found this problem. I do not approve of the fact that he caused four username changes, then a fifth after i was working on fixing it, wasting my time and causing unnecessary commotion. That is just total asshattery and deserves no place in this community.
I'm rather sure the only people affected by strager were Ph0X, ASH, and Larto, whom were all amused by it. (Okay, not sure about Larto). Ph0X was cracking up on Ventrilo as the whole thing was going on, but I understand the issue is more of the fact that you had to be bothered to change it back. strager said he only changed their names, so, unless he's lying, everyone else either did it on their own or someone else was sending out links.
But, from a community perspective, I think the most commotion is being caused by him simply being banned.
Ph0X
Don't want to be protecting him, but to be fair, I was the first test, so that's fine. Mashley shouldn't even count because he actually wanted that name and he changed it back to it again right after anyways. And for Larto, I think I remember peppy saying that he fixed it, and strager quickly tried it on Larto to make sure.
Shinde
Can't he just be banned for like 2-4 weeks etc.? The thought of never seeing strager on osu! again saddens me.

Well, at least there's always Vent.. And cake. Mmyeah. 8-)

SPOILER
Obligatory video. Row Row Fight the Power!

Cuddlebun
I only recall seeing strager change those three people; I was talking to strager and he said the same thing. I'm not defending or condoning his actions, but I don't think strager really meant any serious harm with his actions. A permanent ban seems pretty extreme considering strager could have done a lot worse (ie, gone nuts and changed a huge number) and actually helped peppy fix the loophole before anyone else could seriously exploit it.
mekadon_old

Shinde wrote:

Can't he just be banned for like 2-4 weeks etc.? The thought of never seeing strager on osu! again saddens me.

Well, at least there's always Vent.. And cake. Mmyeah. 8-)
50% to this. 50% to peppy
Seriously, idk what the hell am I writing
peppy
Okay, for the record: strager changed three usernames initially (using a link to his own server which automatically submitted a targeted user's name change request). He then changed a fourth name (Larto's, for the second time) after I initially said I fixed the problem.

I take a similar approach here as I do to people who attempt to cheat osu! rankings: if they warn me first of a potential hole before proceeding with testing of it, I will help as much as possible and allow them to do as they wish. If they go ahead and abuse the system without reporting it (especially if this happens multiple times), I cannot condone their actions nor cover for them.

strager is an active community member, helps a lot with answering support requests and also wrote the OSQ storyboarding script, which is now an integral part of the storyboarding procedure. While I would like to permanently ban in these cases based on policy, I can't see this happening (yes I am a sucker for pain and am too forgiving -- see myst and other cases). I would like to give strager some time-out to consider his actions, though (let us say a week).

I think the end product of this is that
a) username changing is more secure than it ever needed to be (this is a good thing)
b) i have permanently lost any trust in strager (good for me, bad for strager)
c) commotion was caused (this is not such a good thing)

Overall let's call it status-quo, shall we?
Topic Starter
Pokebis
I'm glad you've come to a mutual decision.
STATUS-QUOOOOOO
nardii
:)
Loginer

nardi11011 wrote:

:)
Thanks for sharing.
nardii
You're welcome :D!
Shinde
Can it be time for us to have strager back, please? :?

Just thought I'd put it out thereee. No rush/worriesss.
dkun

Shinde wrote:

Can it be time for us to have strager back, please? :?

Just thought I'd put it out thereee. No rush/worriesss.
Fuck yes.
peppy
Nope, not yet. Locking this as it is pointless; nothing said here will change his return.
Please sign in to reply.

New reply