Official Everybody Edits Forums

Do you think I could just leave this part blank and it'd be okay? We're just going to replace the whole thing with a header image anyway, right?

You are not logged in.

Donate!

pls donate


#1 2019-04-07 09:41:56, last edited by capasha (2019-04-09 09:00:57)

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Everybody Edits leak sensitive information.

I have talked with Xenonetix and the databases doesn't contains updated IP-Addresses, but your old ones still exists.
So now everyone should know that. But below this text is what can be accessed.


Looking at other peoples friends is now patched, thanks to xenonetix and the dev team.

There is a way people with programming knowledge can access:
0] Which world you are inside and the name of the world (Doesn't need to be friend with you)
1] Which the last date you logged in to EE.
2] Your'e last used IP-Address since the last hacking attempt. (Not updated, but they are still there)

How PIOSRT works
PIOSRT found these databases public for everyone to use.
What is PIOSRT? Go to the link and I describe everything about this tool.

Offline

#2 2019-04-07 09:56:12

Crybaby
Formerly minimania
From: Wilted
Joined: 2015-02-22
Posts: 4,376

Re: Everybody Edits leak sensitive information.

mTGpbgv.png


unknown.png
(Click to see my graphics topic)

Offline

#3 2019-04-07 14:22:37, last edited by capasha (2019-04-07 17:01:05)

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Re: Everybody Edits leak sensitive information.

Like title. I said that the database x is open for everyone. And I posted it in a pastebin.
But he said he didn't care. I CARE XENONETIX.

A little chat from Xenonetix:
syNVgoo.png


You don't accept that people need some privacy.

Offline

Wooted by: (4)

#4 2019-04-07 14:27:03, last edited by Tomahawk (2019-04-07 16:35:33)

mikelolsuperman
Member
From: North Korea
Joined: 2016-06-26
Posts: 1,681
Website

Re: Everybody Edits leak sensitive information.

capasha wrote:

So here it come another thing, people shouldn't have access to these database objects.

Ip addresses is removed. Because I don't want other people to use it.
Friends doesn't show which account that have these friends. I want it that way.

A bit from the pastebin.

{
        smiley: 179,
        name: "xenonetix",
        lastUpdate: 2019-04-07 03:31:30,
        ipAddress: censored
        currentWorldName: "",
        currentWorldId: "",
        hasGoldBorder: False,
        stealth: False
}

My Awesome tool that never get released //forums.everybodyedits.com/img/smilies/sad:
<snip - OP request>



The pastebin:
<snip - OP request>

That's from me. Good job at not storing ip addresses, clap clap.

The hacker leaked stuff that's in there. Are you the hacker?


Blue is my favourite color
BhC68b8.png

Signature made by Nebula

I also like lasagna, but not when it's blue

Offline

#5 2019-04-07 14:28:41

Different55
Forum Admin
Joined: 2015-02-07
Posts: 15,995

Re: Everybody Edits leak sensitive information.

Merging with your other thread. Please do not make whole topics for each of your posts about the issue.


"Sometimes failing a leap of faith is better than inching forward"
- ShinsukeIto

Offline

Wooted by:

#6 2019-04-07 14:32:25

Jesse
Member
From: Antartica?
Joined: 2015-02-16
Posts: 69
Website

Re: Everybody Edits leak sensitive information.

Xenonetix wrote:

But there's nothing we can do about that in EE without breaking Friends lists or disabling Friends altogether, such is the nature of crappy PIO

Stop blaming PlayerIO for literally everything. There is something you can do about it, and it's ridiculously easy to implement.
Besides that, if we're comparing this against Facebook; I'm pretty sure Facebook allows you to hide your friends list.


Thanks a lot, Sensei1, for drawing this amazing avatar for me <3

Sig.php

Offline

#7 2019-04-07 14:39:44, last edited by capasha (2019-04-07 16:14:19)

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Re: Everybody Edits leak sensitive information.

mikelolsuperman wrote:
capasha wrote:

So here it come another thing, people shouldn't have access to these database objects.

Ip addresses is removed. Because I don't want other people to use it.
Friends doesn't show which account that have these friends. I want it that way.

A bit from the pastebin.

{
        smiley: 179,
        name: "xenonetix",
        lastUpdate: 2019-04-07 03:31:30,
        ipAddress: censored
        currentWorldName: "",
        currentWorldId: "",
        hasGoldBorder: False,
        stealth: False
}

My Awesome tool that never get released //forums.everybodyedits.com/img/smilies/sad:




That's from me. Good job at not storing ip addresses, clap clap.

The hacker leaked stuff that's in there. Are you the hacker?

Look whos the owner of the pastebin.









Jesse wrote:
Xenonetix wrote:

But there's nothing we can do about that in EE without breaking Friends lists or disabling Friends altogether, such is the nature of crappy PIO

Stop blaming PlayerIO for literally everything. There is something you can do about it, and it's ridiculously easy to implement.
Besides that, if we're comparing this against Facebook; I'm pretty sure Facebook allows you to hide your friends list.

In Facebook you can disable people from looking at your profile and see all friends you have.
EE doesn't. This only makes me mad.

Offline

Wooted by:

#8 2019-04-07 15:14:37

peace
Member
From: admin land
Joined: 2015-08-10
Posts: 6,308

Re: Everybody Edits leak sensitive information.

who cares if anyone sknows thier firends no an crappy sandbox platformer it snot liek i know ANYONE fo my ee firned sin real life


peace.png

thanks hg for making this much better

Offline

Wooted by:

#9 2019-04-07 15:28:43, last edited by capasha (2019-04-07 15:32:54)

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Re: Everybody Edits leak sensitive information.

peace wrote:

who cares if anyone sknows thier firends no an crappy sandbox platformer it snot liek i know ANYONE fo my ee firned sin real life

As the other hack that come out you didn't care either. I care about peoples privacy about the sensitivity information.
People want to know and need to know when their privacy is at a risk or sensitivite information is out.


Anyway. The database keep updating. People can still find in which world people are inside. Even without be he/her friend.
No privacy and just dont give a damn about it either.

Offline

Wooted by:

#10 2019-04-07 15:30:58, last edited by Joeyc (2019-04-07 15:32:29)

Joeyc
Guest

Re: Everybody Edits leak sensitive information.

I don’t really see how keeping friends private or not is such a big deal

#11 2019-04-07 15:36:57

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Re: Everybody Edits leak sensitive information.

Joeyc wrote:

I don’t really see how keeping friends private or not is such a big deal

I don't want people to know which I'm friend with. I want that private for myself.
By knowing which friend i have, people could search on duckduckgo.
Maybe find this users nickname and can then later maybe know who it is.
Maybe my mom use that nickname? Who knows.

Offline

#12 2019-04-07 15:45:50

Crybaby
Formerly minimania
From: Wilted
Joined: 2015-02-22
Posts: 4,376

Re: Everybody Edits leak sensitive information.

It would be really unfortunate if someone who was stalking me found out who my friends were, and which ones were active enough to ask how to find me in other places.


unknown.png
(Click to see my graphics topic)

Offline

#13 2019-04-07 15:46:03

mrjawapa
Member
From: Ohio, USA
Joined: 2015-02-15
Posts: 5,156
Website

Re: Everybody Edits leak sensitive information.

Security and privacy is great, but are we really **** about our friends list being public? And why are we blaming ML for this? Have friends lists not always been public?

This is turning into a witch hunt


jmz85ffh.png

Offline

Wooted by:

#14 2019-04-07 15:47:25, last edited by Crybaby (2019-04-07 15:47:49)

Crybaby
Formerly minimania
From: Wilted
Joined: 2015-02-22
Posts: 4,376

Re: Everybody Edits leak sensitive information.

mrjawapa wrote:

Have friends lists not always been public?

They never were (if we're talking about EE)


unknown.png
(Click to see my graphics topic)

Offline

#15 2019-04-07 15:51:37

mrjawapa
Member
From: Ohio, USA
Joined: 2015-02-15
Posts: 5,156
Website

Re: Everybody Edits leak sensitive information.

Crybaby wrote:

They never were (if we're talking about EE)

Then when did it change?


jmz85ffh.png

Offline

#16 2019-04-07 15:56:58

Tomahawk
Forum Mod
From: BiH
Joined: 2015-02-18
Posts: 2,179

Re: Everybody Edits leak sensitive information.

It's not so much that a player's friend list is super private information that must be kept secret at all costs, but rather that the player cannot choose to keep it secret if they want to.

It is personal data, and at the risk of being one of those guys that quotes legislation, in the UK personal data must be:

Data Protection Act 2018 wrote:

handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage.

Maybe they can do something about it, maybe they can't. It's still an issue.

Capasha seems to like publicising security flaws with no consideration of whether those flaws are better kept private. In the real world one process is to inform the relevant company of the weakness, give them X months to fix the issue and THEN publicise it, if only to put pressure on them to fix it quickly. But nah, remember when OP semi-leaked Cercul1's password?


One bot to rule them all, one bot to find them. One bot to bring them all... and with this cliché blind them.

Offline

Wooted by: (4)

#17 2019-04-07 16:07:41

Crybaby
Formerly minimania
From: Wilted
Joined: 2015-02-22
Posts: 4,376

Re: Everybody Edits leak sensitive information.

mrjawapa wrote:

Then when did it change?

Okay, after a few minutes, I need to think more about this, because I might have misspoke.

There is no feature in Everybody Edits that shows other players your friend's list. Without third-party software, one's friend's list is private as long as the user doesn't share that information with others themselves.

I'm not too good at doing talking so forgive me


unknown.png
(Click to see my graphics topic)

Offline

Wooted by:

#18 2019-04-07 16:10:15

NorwegianboyEE
Member
From: Norway
Joined: 2015-03-16
Posts: 1,963

Re: Everybody Edits leak sensitive information.

If you care so much about your private data you should join the opt out village.

Offline

Wooted by:

#19 2019-04-07 16:13:40, last edited by capasha (2019-04-07 16:59:40)

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Re: Everybody Edits leak sensitive information.

Tomahawk wrote:

It's not so much that a player's friend list is super private information that must be kept secret at all costs, but rather that the player cannot choose to keep it secret if they want to.

It is personal data, and at the risk of being one of those guys that quotes legislation, in the UK personal data must be:

Data Protection Act 2018 wrote:

handled in a way that ensures appropriate security, including protection against unlawful or unauthorised processing, access, loss, destruction or damage.

Maybe they can do something about it, maybe they can't. It's still an issue.

Capasha seems to like publicising security weaknesses with no consideration of whether those weaknesses are better kept private. In the real world one process is to inform the relevant company of the weakness, give them X months to fix the issue and THEN publicise it, if only to put pressure on them to fix it quickly. But nah, remember when OP semi-leaked Cercul1's password?

I semi-leaked Cercul1's password? When?
Anyway I removed the Image and pastebin because feels better like that.

Edit: Updated title and first post. Because I feel like I write it better so people understand instead of just leaking information.

mrjawapa wrote:

Security and privacy is great, but are we really **** about our friends list being public? And why are we blaming ML for this? Have friends lists not always been public?

This is turning into a witch hunt

I have used this tool little from and back. And friends list that everyone can read have never been that before.

NorwegianboyEE wrote:

If you care so much about your private data you should join the opt out village.
https://youtu.be/lMChO0qNbkY

Who even use Google?

Offline

#20 2019-04-07 17:06:49

peace
Member
From: admin land
Joined: 2015-08-10
Posts: 6,308

Re: Everybody Edits leak sensitive information.

capasha wrote:

Who even use Google?

who not?


peace.png

thanks hg for making this much better

Offline

Wooted by:

#21 2019-04-07 17:39:15

Kikikan
Member
From: Hungary
Joined: 2015-08-10
Posts: 194

Re: Everybody Edits leak sensitive information.

I'm waiting for EEU, so the staff won't be able to blame anyone (mainly PlayerIO) but themselves, and actually has to come up with solutions.

peace wrote:

who not?

People who care about their privacy.

Offline

#22 2019-04-07 21:55:57

mrjawapa
Member
From: Ohio, USA
Joined: 2015-02-15
Posts: 5,156
Website

Re: Everybody Edits leak sensitive information.

Tomahawk wrote:

It's not so much that a player's friend list is super private information that must be kept secret at all costs, but rather that the player cannot choose to keep it secret if they want to.

Why does it matter? What difference does it make if people know who your friends are?

Tomahawk wrote:

Capasha seems to like publicising security flaws with no consideration of whether those flaws are better kept private.

It cannot be stressed enough, just how retarded this is.

>muh privacy
>here's a step by step on how to access the information I don't want people to access


jmz85ffh.png

Offline

Wooted by:

#23 2019-04-09 09:02:06

capasha
Member
Joined: 2015-02-21
Posts: 3,814

Re: Everybody Edits leak sensitive information.

Getting peoples friends without be friend with them is now patched. Thanks to xenonetix and the team.

Offline

Wooted by: (2)

#24 2019-04-09 09:55:26

Zumza
Member
From: root
Joined: 2015-02-17
Posts: 4,496

Re: Everybody Edits leak sensitive information.

Tomahawk wrote:

Capasha seems to like publicising security flaws with no consideration of whether those flaws are better kept private. In the real world one process is to inform the relevant company of the weakness, give them X months to fix the issue and THEN publicise it, if only to put pressure on them to fix it quickly.

When they refuse to fix it from the start, like how Xeno did in this case, then clearly after X months everything will be the same. I don't know whether capasha contacted Xenonetix before or after the first post of this topic. Xeno admitted they knew about this, anyhow, so it wasn't a new thing for them.  Therefore the announcement of this issue is justifiable.


Everybody edits, but some edit more than others

Offline

#25 2019-04-09 14:34:11

MWstudios
Member
From: World 4-2
Joined: 2018-04-06
Posts: 1,331

Re: Everybody Edits leak sensitive information.

capasha wrote:

By knowing which friend i have, people could search on duckduckgo.

I dislike Duckduckgo because when I was installing something some time ago, I got a Duckduckgo toolbar along with it and I couldn't get rid of it
So nowadays I compare it to Ask or MyWay


Time before becoming a Member - Leaderboard
1. Whirl - 9 months
2. KirbyKareem - 8 months
3. pwnzor - 2.4 months
4. MWstudios - 2 months
5. ILikeTofuuJoe - 1.5 months
giphy.gif Piskel is the best GIF maker I've seen
HG's signature for me - Anatoly's signature for me
The Mashed Potatoes Song - The longest post on EE forums - Play my Minesweeper

Offline

peace1554961560745591

Board footer

Powered by FluxBB

[ Started around 1571314083.2678 - Generated in 0.079 seconds, 10 queries executed - Memory usage: 1.79 MiB (Peak: 2.08 MiB) ]