Security Lockdown (Wishlist)

Security Lockdown // Wishlist

1  |  

strike rapier

Sep 19, 2002, 3:25pm
Dear Folks,
Over the last few months we have seen a drastic increase in cloning related security problems, by this I also include console messages, and now allowing the world server to modify chat so that sessions apear to be differnt, say differnt things etc etc etc.

When we purchase a citizenship we are under the presumption, that as it says on the webpage. To use a unique citizen name, this is 1 of the biggest, if not the biggest reason to get a citizenship to prevent being impersonated. However despite this Active Worlds is continhjually adding features that allow CT's to "clone" the apearence of users with or without their permission.

As we have already seen with people cloning E N Z O this presents a very real problem, as people can now easily fake images, screenshots, chat logs etc.

For that reason I would like to see the following features:
- A citizen option to "Dissable Copying" that would denny all world servers / users a method of copying a citizen, for example worlds would not be able to modify chat so it apears under another users name.
- Right click popup extension, so that when you right click an avatar or text it brings up the citizen name, citizen number, Cit ppw, and if the user allows it, the coordinates of that user.
- BotLinkEject to allow a citizen to right click and "eject" a bot on his or her PPW for example if PPWs are abused and control has been lost.

d a n

Sep 19, 2002, 4:16pm
I agree with you on that one.

---
D a n

[View Quote]

joeman

Sep 19, 2002, 7:27pm
Cloning cant really be stopped, sorry.

-Joe

[View Quote]

strike rapier

Sep 20, 2002, 3:34pm
I know the proxy can pritty much clone anyone. But I mean changing bots name sos they apear as a actual cit etc.

- Mark
[View Quote]

linn

Sep 20, 2002, 3:50pm
I agree this can get ppl in a lot of trouble cause it "looks" like you said
it sigh
[View Quote]

joeman

Sep 20, 2002, 7:16pm
But, that's also done with this "AWProxy".

-Joe

[View Quote]

strike rapier

Sep 20, 2002, 8:22pm
With 3.4 its done with the server?

- Mark
[View Quote]

joeman

Sep 20, 2002, 8:44pm
Uhm, no, not really. Well, depends. If you want to log any-old-person in,
then, the world would have to be running behind the proxy. But, if you want
to log a citizenship of yours in, or spoof a user, then the world does not
need to be behind the proxy.

-Joe

[View Quote]

strike rapier

Sep 21, 2002, 7:38am
With 3.4 its done with the server?

- Mark
[View Quote]

strike rapier

Sep 21, 2002, 7:45am
I mean with actually directly impersonating someone in graphics only.

For example you can knock the brackets off a bot to make it look as though its the real person.

- Mark
[View Quote]

joeman

Sep 21, 2002, 2:51pm
No, any version, it can be done with just the "bot" or browser running
through the proxy.

-Joe

[View Quote]

strike rapier

Sep 21, 2002, 3:02pm
Yes, but its "Designed" to be done like that in newer versions, who in gawds name knows how to proxy it and the whole protocal / RC4 scheme to do that
[View Quote]

the derek

Sep 21, 2002, 8:12pm
the left click should not bring up the avatar pop-up menu if it is a console
message. Also indenting all console meaages a little should be enough to
prevent impersonating. And you can already fake chat logs anyway
[View Quote]

technozeus

Nov 25, 2002, 1:35am
That's a good idea. Even if the bot driven console messages were mandatorily indented the size of a single space character, that would be enough to let people see that something's "different" so they would know to think more about such things.

TechnoZeus

[View Quote]

1  |  
Awportals.com is a privately held community resource website dedicated to Active Worlds.
Copyright (c) Mark Randall 2006 - 2024. All Rights Reserved.
Awportals.com   ·   ProLibraries Live   ·   Twitter   ·   LinkedIn