LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 No sense flogging a horse who painted his own sign, "Please Flog Me," and put it on his own behind.You brought up the topic, and divinenature asked to see the what I did. H.
wenglund Posted March 5, 2012 Posted March 5, 2012 (edited) Nah, I don't think you are understanding.Let us say, for a moment, that the only possible vulnerability points to the system were the basic ones (in other words, let's assume the system could not be hacked).Now let's look at all the possible ways to get around that. The first, and obvious one, is to enter in slightly wrong data. Change their birthdate. Change their birth location. Maybe even change their name by one or two letters. There are thousands of possible ways to alter the data so it is unrecongizable for the computer. And even the recognizable ones can generate alot of false positives. There are seven people precisely with my exact name, with my exact birthdate, that go to a certain place to get glasses, just in my state. If that's consistent, think about all the other possibilities. Even if names with close to if not resemblant names were flagged, then, somebody has to go through them all, because obviously, the system is going to pick up some wrong things. Considering how many people that is, that's going to cost something. And that is only with names. What about other slightly off information? There are so many different possible scenarios, that doing that would be somewhat of a nightmare. And all the while, people are looking for ways around your software. And there's many more people looking for ways around it than there are people fixing it.There are other problems too. Let's say they removed the option to insert non-family members. How many people genuinely are inserted per year that are not family members? Alot. That means the work has to be done manually, and that's more paperwork, and thus, more money. Not to mention, that people can still insert people who aren't family members as family members. How do we check that? We can't set up any form of ID to check whether the person is actually a family member (that'd be a breach of privacy), so we have to do yet more flagging and more manual work, which costs yet more money.Let's even say, for a moment, that they required voice permission inserts. What if someone faked the voice insert? How do you verify that? You can't go spying in on their home. And you'd still have to make sure people listened to it to make sure it wasn't garbage (yet more money). Or what if we required lots of background information, to be sure? Well, how are we sure that all people have alot of background information? We aren't. And even then, we'd have to check they didn't copy it from elsewhere, are we to perform a comparison check on every single entry in the database? That's a HUGELY expensive operation. You don't want your servers doing things like that. Even if we eliminate some of the unlikeliest ones, that's alot of data to check. The fact is, changing a few small things takes only a tiny bit of effort. Whereas, it takes the server (or humans) alot of effort to weed out.Now, let me make an analogy to the independent flash game industry, which I am trying to get into. Now mind you, I don't have any multiplayer games. But I know (and talk to) alot of developers who do. Now, one of the major problems in these games is hackers. Now, we can provide a few checksums to see if they are accessing the correct data, and double check that the weapon stats are right. We can ensure that things are done on the client side, to make it harder to access (because data has to be inserted at precise moments). And we can do many other things to prevent hacking and manipulating of data to allow a fun multiplayer experience. Now, what does it all come up to? There are just less hackers. Not alot less, mind you, only some less. Why? Because hacking programs are distributable, and once one person makes one, many others use the same program. So there are still hackers, and the hackers don't even have to have a knowledge of hacking. They just have to have a knowledge of where a package you have to download is, and how to use it. Ultimately, the life lesson learned is that you can't prevent everything through code; computers aren't just smart enough. They only prevent people who don't have a truly compelling interest.Now, there is another technique the developers use against hackers - reporting. This is the most effective technique, because people can learn and recognize patterns very quickly, while computers can't. If a hacker is reported, their IP is blocked, their account is deleted. This doesn't always stop them, of course, because they can change computers/networks, but, it does help alleviate the problem. The problem will still exist - and people will still hack - but the problem is always being solved, thanks to people reporting the hackers. Thus, this, is the best way to block hackers to date. It's alot less time consuming then rewriting the software to make their hacking programs not work. It isn't permanent. It ins't a catch all. But it works.The thing is, I think the church is already doing this, right? They already let users report errors like this?So to sum things up, here it goes:1) Fixing these problems isn't going to stop people who are already sufficiently motivated to submit incorrect data. At most, it will stop ones who are either non-tech-savy, or are just doing it as a joke.2) The amount of fixes and combinations of ways to make errors is gigantic, and just impractical to incorporate into a program. It'd make things very slow, and very expensive.3) The church is already employing the most practical approach of the problem: letting users report data that has been incorrectly submitted4) The more restrictive the system, the more of a hassle it is for the user base that is supposed to be accessing the software. You are a software developer, so you should know that making things difficult is not a good idea.Conclusion: Regardless of your intentions, you have not created an appropriate solution for the problem (the ones I see are either expensive, hasslish, or impractial,and we can't use those =/). Thus, I do not see why you should be criticizing it. You need to come up with a truly practical solution, and then we can start talking, and most definitely will start talking =).Darn. I was hoping he would make the arduous attempt to fashion a solution only to in the end figure out what you just said. That way he may be more sure to learn his lesson. Then again, maybe that is what it will take anyway. We'll see--that is, assuming he isn't disingenuous in his desire to fix what he sees as a problem.Thanks, -Wade Englund- Edited March 5, 2012 by wenglund
Bob Crockett Posted March 5, 2012 Posted March 5, 2012 Yes, I'm an apostate. And?How was Church today? You're a high councilor, aren't you?
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 Darn. I was hoping he would make the arduous attempt to fashion a solution only to in the end figure out what you just said. That way he may be more sure to learn his lesson. Then again, maybe that is what it will take anyway. We'll see--that is, assuming he isn't disingenuous in desire to fix what he sees as a problem.Thanks, -Wade Englund-I have fashioned such systems in my professional life. The key is matching the level of security and restriction to the requirements of both user and business. Guys, it isn't an unsolvable problem and it's not magic. H.
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 How was Church today? You're a high councilor, aren't you?I was. And I served in a stake presidency. I no longer attend church. And I resigned my calling. And spoke to my bishop and turned in my temple recommend.So, yes, I am an apostate, by definition.H.
Anijen Posted March 5, 2012 Posted March 5, 2012 Yes, I'm an apostate. And?Why are you still in the church? Send in your letter...
Storm Rider Posted March 5, 2012 Posted March 5, 2012 Why are you still in the church? Send in your letter...Anijen, that is not an appropriate question. It is, imho, not a Christlike attitude toward those who have fallen away from an understanding of the Church in most circumstances. Please be the source of peace you normally are on this forum. It is not always easy, but it is what being a disciple of Christ is all about. Lest you think I am speaking from a position of having achieved it, please understand that I am the worst of the lot here. I just understand how much it helps when brothers and sisters extend a hand of fellowship along the way. 1
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 Why are you still in the church? Send in your letter...I will in due time. For now, I see no need to resign. Perhaps I'll face church discipline for my blog post. If so, I will record my interviews and council.H.
TAO Posted March 5, 2012 Posted March 5, 2012 (edited) 1. Use a loose pattern matching algorithm to check submissions against a list of restricted names. Such lists are easily obtainable.I explained in my post how this was easy to circumvent by adding, reducing, or changing letters. For example:a. Annie Frankb. Ann Frankc. Annie_Frankd. Anne Franke. Anie Franketc.This also happens to be the reason why it is close to impossible to completely ban bad words in chats.2. Sequester names that are flagged as possible matches.I mentioned this as well. If you have a system that does broad flags (so it catches some of the above), it will be rather expensive to have a bunch of people go through and check all of them. If you have a system that does strict flags, you'll have alot that fall through.3. Do a more thorough check on sequestered names. This can be done low-cost - have service missionaries do it. Create a protocol that checks for verifies proof of permission.I disagree that it can be done at a low cost, especially if thorough. Again, how many different ways is it possible to circumvent the system? Alot. This means, rather than just have them go through the flags, you have to make them peruse the millions of names on the system instead. That's a much broader category. What happens when they make a mistake? It gets deleted. Genealogical Information is rather precious, is it not, though? So, have a backup server? More Money. Have people go through the backups? More money. What about how long do you keep backups? More money. Money just adds up.Yes, this system can be circumvented. But it would take much more effort to circumvent than the current system.It would take almost no more effort than the current system. It just means you have to use your brain a bit, and not enter the obvious things. I wouldn't be surprised if people were already doing this. Edited March 5, 2012 by TAO
Duncan Posted March 5, 2012 Posted March 5, 2012 I will in due time. For now, I see no need to resign. Perhaps I'll face church discipline for my blog post. If so, I will record my interviews and council.H.if you aren't active would they do anything to your membership? I would just imagine they would leave you be
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 if you aren't active would they do anything to your membership? I would just imagine they would leave you beNot necessarily - i've been in disciplinary councils were people were inactive and still ex'd because of stuff they did.
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 I explained in my post how this was easy to circumvent by adding, reducing, or changing letters. For example:a. Annie Frankb. Ann Frankc. Annie_Frankd. Anne Franke. Anie Franketc.This also happens to be the reason why it is close to impossible to completely ban bad words in chats.Sigh... if you are going to crack into this industry, you need to think a bit wider - of course names are easy to change up, but when you couple the name with birth dates, birth places, death dates, death places, you get a fairly good match.As for the rest of your refutation - like I said earlier - the church doesn't need to build NSA level security, but it shouldn't leave the front door open either.H.
TAO Posted March 5, 2012 Posted March 5, 2012 (edited) Sigh... if you are going to crack into this industry, you need to think a bit wider - of course names are easy to change up, but when you couple the name with birth dates, birth places, death dates, death places, you get a fairly good match.As for the rest of your refutation - like I said earlier - the church doesn't need to build NSA level security, but it shouldn't leave the front door open either.H.Too simplistic. What if in addition to the name, I changed the date of birth, date of death by 1 date, then changed the places by a letter or so too.This takes virtually no effort for the user. They are already keen on deceiving the system; what's changing one letter worth?Of course the church doesn't need an NSA system, but things are still going to get through, and people are still going to get offended by them.Fixing a few problems like these isn't really going to stop people who want to insert names, I think. Again, you'd have to do studies to prove that, but, it isn't all that hard to do things to get around it. Ultimately, I am guessing the church already has a system in place, they just don't do it via software. I could be wrong there, but that's what my guess is. Edited March 5, 2012 by TAO
mfbukowski Posted March 5, 2012 Posted March 5, 2012 ...I'm sorry then I guess? Unless you're saying that with some sarcasm that I missed, tad bit of an over-reaction there my friend.With the attention that's being drawn to this topic right now, I would think, in my opinion, that the letter from the First Presidency should be read and not just simply posted. That way more members could have an idea about what's going on with this.EDIT: Because I guess some people need me to indicate that it's my opinion I'm expressing.Sorry you got the brunt of that but in reality you were about the 4th or 5th person who said the same thing.This is actually a very esoteric point- how many members have holocaust survivor ancestors? The church had to do something so it issued the letter but there are actually very few who it will affect. So it suggested it be posted rather than causing controversy in the middle of sacrament meeting.Makes sense to me.
mfbukowski Posted March 5, 2012 Posted March 5, 2012 The Church made a reasonable commitment that it has reasonably kept. That should have sufficed--except, perhaps, for those with an ax to grind or polemic points to score.Thanks, -Wade Englund-Or a website that encourages every wacko out there to do exactly what the church is trying to avoid.
mfbukowski Posted March 5, 2012 Posted March 5, 2012 You brought up the topic, and divinenature asked to see the what I did.H.See that big cliff over there?.......
Duncan Posted March 5, 2012 Posted March 5, 2012 Sorry you got the brunt of that but in reality you were about the 4th or 5th person who said the same thing.This is actually a very esoteric point- how many members have holocaust survivor ancestors? The church had to do something so it issued the letter but there are actually very few who it will affect. So it suggested it be posted rather than causing controversy in the middle of sacrament meeting.Makes sense to me.me Dad is German and his uncle was imprisoned during the war for being a German Communist but he had an interesting story but it wasn't in the holocaust
mfbukowski Posted March 5, 2012 Posted March 5, 2012 (edited) me Dad is German and his uncle was imprisoned during the war for being a German Communist but he had an interesting story but it wasn't in the holocaustYes there were millions of Christian Poles and others who were also killed - I should have specified "Jewish". Edited March 5, 2012 by mfbukowski
Anijen Posted March 5, 2012 Posted March 5, 2012 Anijen, that is not an appropriate question. It is, imho, not a Christlike attitude toward those who have fallen away from an understanding of the Church in most circumstances. Please be the source of peace you normally are on this forum. It is not always easy, but it is what being a disciple of Christ is all about. Lest you think I am speaking from a position of having achieved it, please understand that I am the worst of the lot here. I just understand how much it helps when brothers and sisters extend a hand of fellowship along the way.Hi Storm Rider, I do not mean to come out harsh that is not my intention. I just do not see why he stays in a church that he refuses to follow. “And they were all young men, and they were exceedingly valiant for courage, and also for strength and activity; but behold, this was not all—they were men who were true at all times in whatsoever thing they were entrusted” (Alma 53:20). His fighting against the church is deceiving. I would like him to be open about it and not use the facade of a serious member who wants to do temple work (instead he uses it in a way directly against our church leaders). He boasts how he has gone against the church and the guidance of church leaders, he admits he is an apostate, and he says he will probably eventually write a letter. There is nothing un-Christ like in my asking why he is delaying that. In fact delaying it and continuing to go against the church is in my opinion worse. I think you may be correct if he was lukewarm about it and had some inklings of repentance but I see none of that. I do not think I have offended him. From reading many, many of his posts he seems to enjoy his rebellious attitude. If I have offended you or him with my bluntness I apologize, it was not my intent.Anijen
Popular Post Stargazer Posted March 5, 2012 Popular Post Posted March 5, 2012 LDS Toronto, regardless of what you think you did or didn't do, what you are doing isn't causing progress.Of course you can get around the system. But creating a foolproof system is nigh impossible. There is almost always a way around things. Proving something like this does absolutely nothing at all.I don't really respect people who do things like this, just to annoy people.LDSToronto really annoys me sometimes. But you people are just going way off the deep end in your criticism. In the thread he got banned from I made the claim that this wasn't as malicious as you all seem to believe. Some didn't like my sticking up for him. Tough.What he has done here is effectively what is called a "grey hat" action in the computer biz. Black hats being true computer criminals, white hats being those who specifically work FOR a company to improve their security, and grey hats being those who fall somewhere in the middle:A grey hat, in the hacking community, refers to a skilled hacker whose activities fall somewhere between white and black hat hackers on a variety of spectra. It may relate to whether they sometimes arguably act illegally, though in good will, or to show how they disclose vulnerabilities. They usually do not hack for personal gain or have malicious intentions, but may be prepared to technically commit crimes during the course of their technological exploits in order to achieve better securityIf you discover a security vulnerability in a software program and contact the maker of the software privately to tell them about it, then you are a white hat. The software maker may then fix the vulnerability and we are all good. But if the software maker ignores the white hat, some of them will wait a period of time and then disclose the vulnerability publicly in order to force the maker to fix the problem. The white hat transitions over to grey hat. There is a long tradition of this. Microsoft has been grey-hatted by folks who tried to point out problems quietly but were ignored. So have other makers.All LDSToronto has done is to bring a problem to emphasis that isn't being adequately addressed (he believes). I don't see this as some sort of nefarious evil act. If he were to discover the hole and then exploit it privately for nefarious purposes then this would be black hat and would be dispicable. He has not. What he has done is semi-responsible. The rest of you people who are happy to exceed the speed limit by 5 miles per hour because you know the police aren't likely to pull you over for it have nothing whatsoever to complain about. The others of you who wouldn't dream of exceeding the speed limit by 1 mile per hour have done it anyway, if only inadvertantly.So stop getting up on your high horses. You sound like a bunch of whiners. 6
TAO Posted March 5, 2012 Posted March 5, 2012 (edited) LDSToronto really annoys me sometimes. But you people are just going way off the deep end in your criticism. In the thread he got banned from I made the claim that this wasn't as malicious as you all seem to believe. Some didn't like my sticking up for him. Tough.What he has done here is effectively what is called a "grey hat" action in the computer biz. Black hats being true computer criminals, white hats being those who specifically work FOR a company to improve their security, and grey hats being those who fall somewhere in the middle:Grayhatting is a term usually referring to hackers. He wasn't hacking. But you are talking about non maliciousness. However, I wasn't criticizing him for finding things in the software. Instead, I was criticizing him for what he was doing being purposeless. It is pretty much impossible to perfectly fix software that does this sort of work when it needs open data like this. We don't have records we can verify from, and there are things you can easily manipulate to get around small checks for misinformation. Thus, the work has to be done manually.If you discover a security vulnerability in a software program and contact the maker of the software privately to tell them about it, then you are a white hat. The software maker may then fix the vulnerability and we are all good. But if the software maker ignores the white hat, some of them will wait a period of time and then disclose the vulnerability publicly in order to force the maker to fix the problem. The white hat transitions over to grey hat. There is a long tradition of this. Microsoft has been grey-hatted by folks who tried to point out problems quietly but were ignored. So have other makers.This wasn't a bug though. The software is intended to have very open capabilities. And the things we need to restrict are very very very difficult to implement - so much that developer teams these days tend to ignore them, and instead use users to find what they are looking for.In other words, the problem the public is having is pretty much unsolvable. Because it takes very little effort to get around the things we do to stop it, whereas it takes a lot of effort on our side in order to block such a simple thing.All LDSToronto has done is to bring a problem to emphasis that isn't being adequately addressed (he believes). I don't see this as some sort of nefarious evil act. If he were to discover the hole and then exploit it privately for nefarious purposes then this would be black hat and would be dispicable. He has not. What he has done is semi-responsible.He's not a black hat. But he's trying to criticize with something that isn't practical to fix. He knows that too. I'm sorry if you feel I'm too cross with him.So stop getting up on your high horses. You sound like a bunch of whiners.I'm not whining - trust me. I'm just a tiny bit irritated. Like when cats get irritated. Their eyes become narrow, and their faces become cross. They lean backward to move their head away. Edited March 5, 2012 by TAO 1
toon Posted March 5, 2012 Posted March 5, 2012 My motive was to show that "a great deal of deception and manipulation" is not required to bypass the Church's safeguards, . . .So in order to show that a "great deal of deception and manipulation" was not necessary, you engagled in a deliberate act of deception and manipulation. So in other words, this is an argument over that a "great deal" means? Seems to me that an intentional act of deception is an intentional act of deception.
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 Too simplistic. What if in addition to the name, I changed the date of birth, date of death by 1 date, then changed the places by a letter or so too.This takes virtually no effort for the user. They are already keen on deceiving the system; what's changing one letter worth?Of course the church doesn't need an NSA system, but things are still going to get through, and people are still going to get offended by them.Fixing a few problems like these isn't really going to stop people who want to insert names, I think. Again, you'd have to do studies to prove that, but, it isn't all that hard to do things to get around it. Ultimately, I am guessing the church already has a system in place, they just don't do it via software. I could be wrong there, but that's what my guess is.If you change the dates, then you aren't putting the person you intend to put into the system. That's one way to deal with that. The other way is to build a tolerance into the system. For birth/death locations, the church already has a pretty good name matching system in place - you can see what I mean by typing in, say, a misspelled Russian town. Sometimes simple works, Tao. Just wondering, when you've written this type of commercial software, what did you do to solve some of these problems? You seem to be pretty good at saying what won't work, but you haven't given much in terms of what will work.H.
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 So in order to show that a "great deal of deception and manipulation" was not necessary, you engagled in a deliberate act of deception and manipulation. So in other words, this is an argument over that a "great deal" means? Seems to me that an intentional act of deception is an intentional act of deception.Yes, that is my argument. I admit that in the article and I've admitted it here. And I think I showed that "a great deal of deception and manipulation" is not required.H.
LDSToronto Posted March 5, 2012 Author Posted March 5, 2012 Hi Storm Rider, I do not mean to come out harsh that is not my intention. I just do not see why he stays in a church that he refuses to follow.His fighting against the church is deceiving. I would like him to be open about it and not use the facade of a serious member who wants to do temple work (instead he uses it in a way directly against our church leaders). He boasts how he has gone against the church and the guidance of church leaders, he admits he is an apostate, and he says he will probably eventually write a letter. There is nothing un-Christ like in my asking why he is delaying that. In fact delaying it and continuing to go against the church is in my opinion worse. I think you may be correct if he was lukewarm about it and had some inklings of repentance but I see none of that.I do not think I have offended him. From reading many, many of his posts he seems to enjoy his rebellious attitude. If I have offended you or him with my bluntness I apologize, it was not my intent.AnijenI am not offended. But I am not boasting about what I did. In fact, I did not post what I did until I was asked by Bob Crockett and divinenature. if anything, I was baited into publishing a link to my work and have received nothing but grief. No matter - I have thick skin and I stand behind what I did.H.
Recommended Posts