Announcement

Collapse
No announcement yet.

Suggestion: Main Website and Forum Security

Collapse
X
  • Filter
  • Time
  • Show
Clear All
new posts

  • Suggestion: Main Website and Forum Security

    Given the forces arrayed against Jeremy, he and his staff can never be too careful, especially since we have entrusted our e-mail addresses and the password for the accounts we are using right now on this website to them and whatever database service they are utilizing. So with that said, I hope you guys have basic protections that prevent database querying attacks such as SQL Injection. If you guys use Tokens when transferring data or accessing accounts, do be aware of spoofing tactics. Honestly, just look up the OWASP list of types of most common attacks of the previous years via your favorite search engines.

    Lastly, please be aware of common social engineering tactics. Please deeply consider how your account recovery tools work and your options when it comes to being DDOSed. I may just be overly paranoid and I know that these methods of attacks are not the usual MO from the factions against Jeremy, but if Exclusively Games is going to become the foundation for something truly great that everyone can participate in and contribute to in a non ideological manner, security should be a prioritized concern. If people have other viable suggestions or additions don't hesitate to add them. I'm sure the community managers/moderators will see this topic. A Healthy dose of paranoia can go a long way :^)

    Thanks for reading.

  • #2
    In cases of limited trust (well, at least for the time being) you can use a secondary, less important email and an autogenerated password from a password manager. Email is exposed? Not a big deal. Password leaks? Just generate a new one.

    Not saying the site shouldn't be secure (it defenitely should be, as much as possible), it's just you can secure yourself from those threats on your side as well.

    Comment


    • averagedog
      averagedog commented
      Editing a comment
      you are correct. But it is a question of liability that the activists will pounce on if there is a breach.
Working...
X