Post by Zou ۞ on Jul 17, 2019 14:42:45 GMT -5
Hey guys.
It's me, your former admin. Remember me? No? Shit.
Long story short we had some drama and I'd like to go on the record to discuss exactly what happened and why, what this means for the site on a technological level, and next steps.
One of our staff members on site, Ray, was harassed by another former member, Lich. Lich was able to obtain Ray's account information both on Discord and on the actual site. On the site, Ray's staff powers were used to ban all other staff members and Ray's accounts were then deleted. On Discord, Ray's ownership was transferred to Slace (let the memes begin, all bow before the almighty Slace).
Lich subsequently posted an enormous rant about his issues with Ray. I'll only say this once. These issues do not concern me. Ray is a member of staff and more importantly a longtime member of this community. Whatever personal problems Lich had with Ray, this is a safe space for community members such as Ray and any of you as well. To violate that is disgusting, repulsive, and shameful. This should never have happened, and none of you should ever have had to become involved. Ray's personal life is his own, to be shared at his own discretion. His rights as a member of the site were violated, as were all of yours. But there is good news. While what Lich did was unbecoming, he did not hack the site. He was given access to Ray's account by someone who had Ray's passwords. The site is completely secure from a technical standpoint.
To ensure that this does not happen further, I have begun a reconfiguration of the member groups for our site. I first purged everyone from the staff list, then I deleted all of the staff groups. I have now made a new staff group, still titled "Site Staff," and this will function as the new group. It has all the same permissions as the old one, with one major exception. Member groups cannot be changed. The reason for this is I will be seeking a technological solution. There are three options. The first is I find a plug-in for nice and cute mini profiles that are more interactive and just a bit more fun than our original displays. This way we could continue to display ranks without the need for a site staff permission that is dangerous in the wrong hands. The second option is, if I can't find it, I program one myself. I might do this, but it's time consuming so we will see. The third option is I program in a security plugin that did not exist before. I suspect I may do this either way. How it works is it will scan IPs when you log into the site and will require a second password authentication to continue into your account if the IP is drastically different compared to your previous log-in(s).
Discord. We are in discussion on changing it out or on shifting ownership of it and wiping hidden/private messages if we do so. I want to stress it is not a guarantee we are changing it. The change is not an official decision by staff, but a suggestion by me. There are several reasons I suggested it. Firstly, the owner does have a certain degree of supremacy over the other staff. This is unbalanced to begin with because it gives a tremendous power advantage to one staff member when all should be equal. Secondly, transferrence to me is the most neutral and equalizing option because I am not staff, do not intend to become staff, and do not plan to seize an admin status once more. What I am is the site's creator, mechanic, and certainly someone with a vested emotional interest in maintaining the quality, security, and safety of the community that I created. What I want is all of you to have this place as a safe space. I suggested a new Discord because the old one has many private things on it, things I would be able to see if it was transferred to me. I do not want to see any of your private messages. However I have been informed that the original Discord can be wiped clean so that that wouldn't be the case. If we do end up going in this direction, I find this the best possible compromise.
But this isn't set in stone. This is a discussion to be had among the community. I didn't bring it to staff because I am not staff and have no interest in being staff. Moreover it is a decision that very much affects all of you, the community as a whole. You deserve to be included in that discussion. We'll come back to this topic later in the chat to talk it out.
As I said, I have created a new Site Staff group and I'm programming plugins to ensure greater site security. There will be other security measures added too. Many of you do not know this, but I have a backup version of this site that contains copypastas of a lot of people's apps. However it was being maintained by a previous generation of staff. With them mostly gone now, it is two years out of date. Not a big deal, it only takes a couple of days to transfer things over. I will be giving permissions on the backup site to staff here so that they can update it. This way in case of future incidents, your character apps and skill spreadsheets will be secure.
Despite this, you guys need to take an active role too. I urge all of you to save your apps somewhere on your private computers or clouds, just in case. I also urge all of you not to share your passwords with anyone. If you have before, change your passwords now. This is especially true for all staff.
For staff, I suggest we revamp the backup site to be identical to this one in format as well. If we do this, then even if the site suffers great damage we will have a reserve site and will suffer minimal total losses. This is something for staff to discuss, and I am open to being included in this discussion as well if needed.
In the meantime, I've taken charge of this situation but I want it to be clear that my return is not in capacity as the site head admin. I am not staff and I do not intend to grab any power. I am here to serve an advisory role and a mechanic role. When there are site technological issues, I can fix them. I am also here to offer my services to everyone in the character creation process. Having built the system, I don't think it's overkill to say I am the most qualified person on the site to advise throughout the creation process and help guide plotlines to create overarching effects. I'm even building a character who can do this as a sort of quest wizard.
Otherwise, just know that everything is ALL GOOD. We have purged all rogue elements, the site is back in top form, and we'll be running plugin upgrades in the next week or two. It's no exaggeration to say this was probably the messiest situation we've ever had on the site, but that's only testament to our solidity. It took less than a day to fix all of this and from a security standpoint we are already stronger than before it happened.
Let's go back to roleplaying, talking about memes, and general nonsense.
Sincerely,
Your Eternal Ad-Gin, Zou
It's me, your former admin. Remember me? No? Shit.
Long story short we had some drama and I'd like to go on the record to discuss exactly what happened and why, what this means for the site on a technological level, and next steps.
One of our staff members on site, Ray, was harassed by another former member, Lich. Lich was able to obtain Ray's account information both on Discord and on the actual site. On the site, Ray's staff powers were used to ban all other staff members and Ray's accounts were then deleted. On Discord, Ray's ownership was transferred to Slace (let the memes begin, all bow before the almighty Slace).
Lich subsequently posted an enormous rant about his issues with Ray. I'll only say this once. These issues do not concern me. Ray is a member of staff and more importantly a longtime member of this community. Whatever personal problems Lich had with Ray, this is a safe space for community members such as Ray and any of you as well. To violate that is disgusting, repulsive, and shameful. This should never have happened, and none of you should ever have had to become involved. Ray's personal life is his own, to be shared at his own discretion. His rights as a member of the site were violated, as were all of yours. But there is good news. While what Lich did was unbecoming, he did not hack the site. He was given access to Ray's account by someone who had Ray's passwords. The site is completely secure from a technical standpoint.
To ensure that this does not happen further, I have begun a reconfiguration of the member groups for our site. I first purged everyone from the staff list, then I deleted all of the staff groups. I have now made a new staff group, still titled "Site Staff," and this will function as the new group. It has all the same permissions as the old one, with one major exception. Member groups cannot be changed. The reason for this is I will be seeking a technological solution. There are three options. The first is I find a plug-in for nice and cute mini profiles that are more interactive and just a bit more fun than our original displays. This way we could continue to display ranks without the need for a site staff permission that is dangerous in the wrong hands. The second option is, if I can't find it, I program one myself. I might do this, but it's time consuming so we will see. The third option is I program in a security plugin that did not exist before. I suspect I may do this either way. How it works is it will scan IPs when you log into the site and will require a second password authentication to continue into your account if the IP is drastically different compared to your previous log-in(s).
Discord. We are in discussion on changing it out or on shifting ownership of it and wiping hidden/private messages if we do so. I want to stress it is not a guarantee we are changing it. The change is not an official decision by staff, but a suggestion by me. There are several reasons I suggested it. Firstly, the owner does have a certain degree of supremacy over the other staff. This is unbalanced to begin with because it gives a tremendous power advantage to one staff member when all should be equal. Secondly, transferrence to me is the most neutral and equalizing option because I am not staff, do not intend to become staff, and do not plan to seize an admin status once more. What I am is the site's creator, mechanic, and certainly someone with a vested emotional interest in maintaining the quality, security, and safety of the community that I created. What I want is all of you to have this place as a safe space. I suggested a new Discord because the old one has many private things on it, things I would be able to see if it was transferred to me. I do not want to see any of your private messages. However I have been informed that the original Discord can be wiped clean so that that wouldn't be the case. If we do end up going in this direction, I find this the best possible compromise.
But this isn't set in stone. This is a discussion to be had among the community. I didn't bring it to staff because I am not staff and have no interest in being staff. Moreover it is a decision that very much affects all of you, the community as a whole. You deserve to be included in that discussion. We'll come back to this topic later in the chat to talk it out.
As I said, I have created a new Site Staff group and I'm programming plugins to ensure greater site security. There will be other security measures added too. Many of you do not know this, but I have a backup version of this site that contains copypastas of a lot of people's apps. However it was being maintained by a previous generation of staff. With them mostly gone now, it is two years out of date. Not a big deal, it only takes a couple of days to transfer things over. I will be giving permissions on the backup site to staff here so that they can update it. This way in case of future incidents, your character apps and skill spreadsheets will be secure.
Despite this, you guys need to take an active role too. I urge all of you to save your apps somewhere on your private computers or clouds, just in case. I also urge all of you not to share your passwords with anyone. If you have before, change your passwords now. This is especially true for all staff.
For staff, I suggest we revamp the backup site to be identical to this one in format as well. If we do this, then even if the site suffers great damage we will have a reserve site and will suffer minimal total losses. This is something for staff to discuss, and I am open to being included in this discussion as well if needed.
In the meantime, I've taken charge of this situation but I want it to be clear that my return is not in capacity as the site head admin. I am not staff and I do not intend to grab any power. I am here to serve an advisory role and a mechanic role. When there are site technological issues, I can fix them. I am also here to offer my services to everyone in the character creation process. Having built the system, I don't think it's overkill to say I am the most qualified person on the site to advise throughout the creation process and help guide plotlines to create overarching effects. I'm even building a character who can do this as a sort of quest wizard.
Otherwise, just know that everything is ALL GOOD. We have purged all rogue elements, the site is back in top form, and we'll be running plugin upgrades in the next week or two. It's no exaggeration to say this was probably the messiest situation we've ever had on the site, but that's only testament to our solidity. It took less than a day to fix all of this and from a security standpoint we are already stronger than before it happened.
Let's go back to roleplaying, talking about memes, and general nonsense.
Sincerely,
Your Eternal Ad-Gin, Zou