Questor opened this issue on Jul 29, 2004 ยท 17 posts
Armorbeast posted Sat, 31 July 2004 at 5:35 AM
Someone saw this and let me know what was going on...even though the incorrect punctuation does explain itself if you read the full comment,I will try to correct the misunderstanding.I was sent a link by rosity IM from a friend who wanted me to check their image.However,I missed the IM and did not realise the mistake for two weeks...I clicked the link and found myself logged as her on her page.I see no confusion here,even for the bad punctuation,the comment does clarify itself when read and you of all people know you don't send me links to view your images...nor would I think that since you know me you would even consider that I would tell such a lie about you. But even as such,you did not address the issue as you said clearly that to avoid this cookies should be enabled...my cookies are always enabled as are I believe everyone that gets logged in automatically when they arrive on rosity.So obviously that is not the answer.You mention that the session id's expire in a short period of time but two weeks is not short. I am not on the attack Lillian and I like you well enough that I wouldn't jump on you,but this is a serious matter not only to us...but to merchants on rosity who could be losing hundreds or even thousands of dollars each from this.If I log in as someone else I can access their downloads...you cannot even legally do anything if it turns out that the members use the same template colors and say they didn't know the download they found in their Gifts Recieved box wasn't theirs.But having sent my session id # out to friends by accident time and again because its not second nature to correct a screwed up url...and having also recieved other members session id #'s,I know how serious this problem is. But rosity isn't the only one...in fact DAZ is worse.Chrislenn sent me a link to a product she wanted me to look at and I found myself listed as her,I not only found I had access to her wishlist but all her personal info also popped up...I told her and got out.About a month later I logged in at DAZ and started having problems accessing my account~I looked and noticed lo and behold I was logged in as Chris again.I did not go to DAZ via a link sent by anyone,I went in through the link on their newsletter and was auto logged in as Chris.I have yet to have that happen here or hear of it from others,but that is a major security issue...so I am not kicking rosity here~its not a problem unique to this site. If I sounded harsh its because the info you gave people to enable cookies and that the session links expire quickly isn't correct...I doubt you knew this or figured it out on your own so I assumed the programmers told you and like I said,programmers are well known to not want to admit they're wrong. Sorry for the miscommunication...I do consider you a friend Lillian but I wasn't talking about you and if you reflect on it you'll realise this.Nor am I bashing rosity...just this is a serious matter and has been since even before I joined and it hasn't been fixed.
If the end goal of learning is genius...why are most geniuses failures at learning?