<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: DarkLife Robbed &#8211; Developer Blames Open Source SL</title>
	<atom:link href="http://alphavilleherald.com/2007/02/darklife_robbed.html/feed" rel="self" type="application/rss+xml" />
	<link>http://alphavilleherald.com/2007/02/darklife_robbed.html</link>
	<description>Always Fairly Unbalanced</description>
	<lastBuildDate>Tue, 04 Oct 2016 13:18:56 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
	<item>
		<title>By: Rock Ramona</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36392</link>
		<dc:creator>Rock Ramona</dc:creator>
		<pubDate>Fri, 02 Mar 2007 15:15:51 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36392</guid>
		<description>hey,ive got a great idea.if everyone came to play The Lord of The Rings Online which will be opening up for open beta March 30th,then you wouldnt have to worry about losing anything,ive played Dark Life and i admire the boys for what they did,where they did,and it makes me sad they got ripped off to,but ll doesnt give a flip about it and they never will,so come have fun with me,go to www.turbine.com for deatils and ill see yall soon!!!
</description>
		<content:encoded><![CDATA[<p>hey,ive got a great idea.if everyone came to play The Lord of The Rings Online which will be opening up for open beta March 30th,then you wouldnt have to worry about losing anything,ive played Dark Life and i admire the boys for what they did,where they did,and it makes me sad they got ripped off to,but ll doesnt give a flip about it and they never will,so come have fun with me,go to <a href="http://www.turbine.com" rel="nofollow">http://www.turbine.com</a> for deatils and ill see yall soon!!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Busch</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36391</link>
		<dc:creator>Mark Busch</dc:creator>
		<pubDate>Fri, 02 Mar 2007 03:03:19 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36391</guid>
		<description>Yeah we&#039;ve figured out a slightly smarter way to secure DarkLife from alt accounts, but I won&#039;t go into details because we&#039;v yet to see how it works in practise :)
</description>
		<content:encoded><![CDATA[<p>Yeah we&#8217;ve figured out a slightly smarter way to secure DarkLife from alt accounts, but I won&#8217;t go into details because we&#8217;v yet to see how it works in practise <img src='http://alphavilleherald.com/site/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wayfinder Wishbringer</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36390</link>
		<dc:creator>Wayfinder Wishbringer</dc:creator>
		<pubDate>Thu, 01 Mar 2007 18:24:04 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36390</guid>
		<description>Hey, that much is true. Although with all the unmoderated and uncontrolled alts running around, sim ban isn&#039;t all that effective any more.  Still, those are really about the shortest and most effective ways I can think of in handling such things. Except of course, for &quot;shut the sucker down and make more reliable investments than SL&quot;.  XD




</description>
		<content:encoded><![CDATA[<p>Hey, that much is true. Although with all the unmoderated and uncontrolled alts running around, sim ban isn&#8217;t all that effective any more.  Still, those are really about the shortest and most effective ways I can think of in handling such things. Except of course, for &#8220;shut the sucker down and make more reliable investments than SL&#8221;.  XD</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Busch</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36389</link>
		<dc:creator>Mark Busch</dc:creator>
		<pubDate>Thu, 01 Mar 2007 18:14:02 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36389</guid>
		<description>will most likely be ignored yeah (still haven&#039;t heard anything from LL yet), but at least you can ban this person, and start thinking about how they gotten the channel number, and if they can abuse it another way :)
</description>
		<content:encoded><![CDATA[<p>will most likely be ignored yeah (still haven&#8217;t heard anything from LL yet), but at least you can ban this person, and start thinking about how they gotten the channel number, and if they can abuse it another way <img src='http://alphavilleherald.com/site/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wayfinder Wishbringer</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36388</link>
		<dc:creator>Wayfinder Wishbringer</dc:creator>
		<pubDate>Thu, 01 Mar 2007 12:28:52 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36388</guid>
		<description>Those are both excellent suggestions.  Especially the thought about the security system informing you if someone tries to hack the channel. Then you have proof positive that can be forwarded as an abuse issue (which will then of course, likely be ignored, but... LOL).

</description>
		<content:encoded><![CDATA[<p>Those are both excellent suggestions.  Especially the thought about the security system informing you if someone tries to hack the channel. Then you have proof positive that can be forwarded as an abuse issue (which will then of course, likely be ignored, but&#8230; LOL).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Busch</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36387</link>
		<dc:creator>Mark Busch</dc:creator>
		<pubDate>Wed, 28 Feb 2007 17:37:19 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36387</guid>
		<description>Thanks, that seems like a good idea!

However the llGetOwner and llGetCreator are also powerfull security measures which should be included as well. When hackers get insight in your scripts (by accident, or by permission bugs from our dear friends at LL) they could look at your hash function, and talk on your channels anyway. Then it&#039;s very nice that your scripts can still detect the false messages, and ignore them as well as inform you, so you can ban and report the abusers.

Also a small addition to your idea would be to slighty let the channel transition overlap. So for 1 minute or so your scripts will listen on both the old AND the new channel. This will allow more &#039;relaxed&#039; checking of the time, and also could prevent loss of messages due to server lag.
</description>
		<content:encoded><![CDATA[<p>Thanks, that seems like a good idea!</p>
<p>However the llGetOwner and llGetCreator are also powerfull security measures which should be included as well. When hackers get insight in your scripts (by accident, or by permission bugs from our dear friends at LL) they could look at your hash function, and talk on your channels anyway. Then it&#8217;s very nice that your scripts can still detect the false messages, and ignore them as well as inform you, so you can ban and report the abusers.</p>
<p>Also a small addition to your idea would be to slighty let the channel transition overlap. So for 1 minute or so your scripts will listen on both the old AND the new channel. This will allow more &#8216;relaxed&#8217; checking of the time, and also could prevent loss of messages due to server lag.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: shockwave yareach</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36386</link>
		<dc:creator>shockwave yareach</dc:creator>
		<pubDate>Wed, 28 Feb 2007 17:16:09 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36386</guid>
		<description>Dear Mark,

The security needs to be in place for financial transactions only.  A better way to make your general system (combat, weaponuse, etc) more secure is to change comm channels every day.

Have a one-way hash function to select the comm channel based on the date, have all the gear use that same function, and sniffing the thousands of channels becomes nearly pointless since the channel will change shortly.  By adding the hour SLT to the mix, everyone can change channels simultaneously every hour instead of every day, meaning even a lucky detection of the channel has less than an hour to exploit it.
</description>
		<content:encoded><![CDATA[<p>Dear Mark,</p>
<p>The security needs to be in place for financial transactions only.  A better way to make your general system (combat, weaponuse, etc) more secure is to change comm channels every day.</p>
<p>Have a one-way hash function to select the comm channel based on the date, have all the gear use that same function, and sniffing the thousands of channels becomes nearly pointless since the channel will change shortly.  By adding the hour SLT to the mix, everyone can change channels simultaneously every hour instead of every day, meaning even a lucky detection of the channel has less than an hour to exploit it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark Busch</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36385</link>
		<dc:creator>Mark Busch</dc:creator>
		<pubDate>Wed, 28 Feb 2007 16:01:54 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36385</guid>
		<description>Thanks for all the informative comments.

LindenLab just informed me (ofcourse AFTER I mailed them again asking for an update) that &quot;the outcome of the investigation as it was determined to fall under the category of abuse&quot;.

Nothing yet said about the actions that were taken. I am very curious if LL attempted to follow the &#039;money-trace&#039;.
It shouldn&#039;t be very hard for them to do. Either the accounts still hold the L$ (in that case I assume it will be returned to my account), or he (or she? naaaa...) gave it to another Avatar. But in the end the money is either still in SL, or it has been sold.
If it was sold, the USD could still be in the &#039;hackers&#039; account (again then I assume I will get it back), or it was deposited to a paypal or check.

In last 2 cases there is little change I&#039;ll see the money again. The chance of getting this guy prosecuted might be small too, but it would be good message to other &#039;hackers&#039; if LindenLab would send there investigation-results to the authoroties of the &#039;hackers&#039; country and/or his ISP, and announce it publicly. Hopefully that will at least give this thief some sleepness nights.

I also hope to hear soon what they did to prevent this guy from coming into secondlife again (and thus DarkLife) because he seemed determined to mess up as much as possible. He (or a friend), using the SL name &#039;Takit Leavit&#039; even payed a DarkLife player to tell our moderators that he was a regular trustworthy DarkLife Player and messed up some darklife-accounts when he came in.

As for security, Yo Brewster is absolutly right, if I would use some sort of security on every piece of communication, the game would not run fast enough. Right now the current version is already too slow sometimes (our new release will be much better on that part) but really, as a game developer you don&#039;t have the luxury of using theoretically good security schemes. If the game becomes too slow to be played then you might as well not build it at all.

In our new release I will use owner and creator checks as much as possible (in the hope that won&#039;t slow it down too much) and I will also build more security checks that hopefully will detect hackers BEFORE they can do any harm. Also we will not use scripts anymore that give out money (that was already in the design, not a result of theft).

Also we already have a pretty good(but still too small) team of moderators who have provem themselved on the latest attack.
They will soon get instructions and tools to search for and ban griefers who try to abuse, cheat or hack on our SIM.
I am confident that, when we open up the game again, we are prepared for future attacks (unless LL does something awefully stupid like introducing another permission-bug).
</description>
		<content:encoded><![CDATA[<p>Thanks for all the informative comments.</p>
<p>LindenLab just informed me (ofcourse AFTER I mailed them again asking for an update) that &#8220;the outcome of the investigation as it was determined to fall under the category of abuse&#8221;.</p>
<p>Nothing yet said about the actions that were taken. I am very curious if LL attempted to follow the &#8216;money-trace&#8217;.<br />
It shouldn&#8217;t be very hard for them to do. Either the accounts still hold the L$ (in that case I assume it will be returned to my account), or he (or she? naaaa&#8230;) gave it to another Avatar. But in the end the money is either still in SL, or it has been sold.<br />
If it was sold, the USD could still be in the &#8216;hackers&#8217; account (again then I assume I will get it back), or it was deposited to a paypal or check.</p>
<p>In last 2 cases there is little change I&#8217;ll see the money again. The chance of getting this guy prosecuted might be small too, but it would be good message to other &#8216;hackers&#8217; if LindenLab would send there investigation-results to the authoroties of the &#8216;hackers&#8217; country and/or his ISP, and announce it publicly. Hopefully that will at least give this thief some sleepness nights.</p>
<p>I also hope to hear soon what they did to prevent this guy from coming into secondlife again (and thus DarkLife) because he seemed determined to mess up as much as possible. He (or a friend), using the SL name &#8216;Takit Leavit&#8217; even payed a DarkLife player to tell our moderators that he was a regular trustworthy DarkLife Player and messed up some darklife-accounts when he came in.</p>
<p>As for security, Yo Brewster is absolutly right, if I would use some sort of security on every piece of communication, the game would not run fast enough. Right now the current version is already too slow sometimes (our new release will be much better on that part) but really, as a game developer you don&#8217;t have the luxury of using theoretically good security schemes. If the game becomes too slow to be played then you might as well not build it at all.</p>
<p>In our new release I will use owner and creator checks as much as possible (in the hope that won&#8217;t slow it down too much) and I will also build more security checks that hopefully will detect hackers BEFORE they can do any harm. Also we will not use scripts anymore that give out money (that was already in the design, not a result of theft).</p>
<p>Also we already have a pretty good(but still too small) team of moderators who have provem themselved on the latest attack.<br />
They will soon get instructions and tools to search for and ban griefers who try to abuse, cheat or hack on our SIM.<br />
I am confident that, when we open up the game again, we are prepared for future attacks (unless LL does something awefully stupid like introducing another permission-bug).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: IntLibber Brautigan</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36384</link>
		<dc:creator>IntLibber Brautigan</dc:creator>
		<pubDate>Wed, 28 Feb 2007 15:04:04 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36384</guid>
		<description>Known Patriotic Nigra, aka /b/, griefer Chirp Chirnov, banned from SL, also now known as Enron Dagger, is likely behind this hack, as Chirp was first developing techniques for messing with weapons system messaging back in January, which enabled him to scan for the Laura Weapons System message channels used by Goreans, and to send them faked messages that killed his victims. This isn&#039;t the first time someone has developed this particular hack, that I know of, but its the first time an outsider has used this ability for malicious purposes. The griefers do have the ability to scan millions of channels, and likely did use this method to hack into the system.

If Chirp isn&#039;t directly responsible, it is likely he, as Enron Dagger, shared this information with others.
</description>
		<content:encoded><![CDATA[<p>Known Patriotic Nigra, aka /b/, griefer Chirp Chirnov, banned from SL, also now known as Enron Dagger, is likely behind this hack, as Chirp was first developing techniques for messing with weapons system messaging back in January, which enabled him to scan for the Laura Weapons System message channels used by Goreans, and to send them faked messages that killed his victims. This isn&#8217;t the first time someone has developed this particular hack, that I know of, but its the first time an outsider has used this ability for malicious purposes. The griefers do have the ability to scan millions of channels, and likely did use this method to hack into the system.</p>
<p>If Chirp isn&#8217;t directly responsible, it is likely he, as Enron Dagger, shared this information with others.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wayfinder Wishbringer</title>
		<link>http://alphavilleherald.com/2007/02/darklife_robbed.html/comment-page-2#comment-36383</link>
		<dc:creator>Wayfinder Wishbringer</dc:creator>
		<pubDate>Wed, 28 Feb 2007 06:48:17 +0000</pubDate>
		<guid isPermaLink="false">http://localhost/wp_2/?p=1479#comment-36383</guid>
		<description>(I gotta start proofreading these posts. Spelling was awful. LOL)
</description>
		<content:encoded><![CDATA[<p>(I gotta start proofreading these posts. Spelling was awful. LOL)</p>
]]></content:encoded>
	</item>
</channel>
</rss>

