on which you can talk in real-time with other Chiff & Fipple Forums members.
There’s also a new statistic in the little block of statistics on the right of the front page such that you can see how many people are chatting before you connect. The number is also listed on the chat login screen.
I imagine that Dale will eventually organize scheduled chats (although anyone is free to do so!), but for the time being, it’s a free-for-all.
Special thanks go to stimpy and the Vancouver Supercomputing Apartment for the use of their chat server, and to David Leadbeater for the chat interface.
As usual, please let me know if you find anything wonky.
Rich, is there not some way to secure our user names with the chat room? I don’t feel comfortable with the fact that, as an experiment, I logged into it just now as “JessieK” with no problems. That is not a good thing at all!!!
On 2002-01-13 22:05, Feadan wrote:
Rich, is there not some way to secure our user names with the chat room? I don’t feel comfortable with the fact that, as an experiment, I logged into it just now as “JessieK” with no problems. That is not a good thing at all!!!
I’d prefer to trust the members of the community first, and put time in to protect everyone from everyone else only when people demonstrate that they can’t play nice.
Thanks for pointing out to anyone that wants to abuse the system precisely how easy it is to do so, though.
On 2002-01-13 22:14, rich wrote:
Thanks for pointing out to anyone that wants to abuse the system precisely how easy it is to do so, though.
Well, Rich, as a person who helps manage computer labs in academic situation it has been my experience that anyone intending malice will find the means to do so rather quickly. 99.99% of the people that post here will do so responsibly. But it has also been my experince that there, over time, is usually “one in every crowd”. I’m sorry you are displeased with what I have pointed out in front of the masses, but it is only fair that all the “good” people should know. Those with less than good intentions would figure it out pretty quickly whether I posted this or not. Funny, I thought this observation would actually be helpful.
Well, Rich, as a person who helps manage computer labs in academic situation it has been my experience that anyone intending malice will find the means to do so rather quickly.
And given your academic computing experience, do you think that the users of the message board present the same risk scenario as a bunch of undergrad students? I don’t.
Those that would care in the first place have enough vested in the community to not put it at risk, and those that don’t have much vested in their reputation in the community don’t have much of an incentive to pretend they’re someone else in a very small IRC channel with a handful of nontechnical users in it.
If credentials matter, I’m a professional Unix system administrator with experience in academia as well as the private sector, and and an IRC user for the past ten years. I’m not satisfied that that’s a risk that needs addressing yet, so I’m going to allocate my volunteer time to address that when it becomes a real, not theoretical, problem.
And since we’re going for disclosure anyhow: no matter how much verification I put on the web interface, one needs only start up an IRC client and connect as instructed on the chat login page to bypass it.
Look, Rich, I’m not trying to bandy about credentials here. I was only trying to provide a basis of experience. I’m confident that you know more about chat rooms in your little finger than I could probably ever hope to. I thought, in my ignorance, I was pointing out something that would be an easy fix. I was meerly trying to be helpful and obviously have instead pissed you off. In case it is not obvious yet, I am truly sorry.
On 2002-01-13 23:05, Feadan wrote:
Look, Rich, I’m not trying to bandy about credentials here.
I was probably a little terse as well, for which I apologize. What I mean to say is that limiting things that way is considerably more difficult than the benefits it reaps, and that it was considered while implementing it – and that the lack of authentication is the result of an informed decision, not of omission.
(There’s a decent crowd on right now, by the way. )
-Rich
[ This Message was edited by: rich on 2002-01-13 23:23 ]
On 2002-01-13 23:13, rich wrote:
What I mean to say is that limiting things that way is not only far more difficult than the benefits it reaps; and that it was considered while implementing it – and that the lack of authentication is the result of a conscious decision, not of omission.
(There’s a decent crowd on right now, by the way. > > )
Thanks for the smiley, Rich, I needed that It sounds like your decision echos my own sentiments to a superior regarding who should know the passwords of our security program (Deep Freeze). I was an advocate of trust until tighter security was proven necessary. As I indicated, in my ignorance of what you are working with I thought this would be an “easy fix”. I should have realized that someone with the skills ( not to mention the generosity) to host this board would have figured out these stupid details on their own. Again…Sorry man!
[ This Message was edited by: Feadan on 2002-01-13 23:26 ]
There’s not really anything that can be done about the nickname thing. different IRC networks use different software. Some include things like NickServ and ChanServ that hold nicknames and channels for the “creators” of them. However, MagNET is not one of those IRC networks. I run one of the servers on MagNET, and we are a very very small network, and don’t feel the need to do these sorts of things. I for one have had my nick “stimps” for about 12 years on BBSes, Usenet posts, 5 years crossing 2 different IRC servers, and a lot of other venues. If you come on with a nick, and are consistent in using it, people will a) be able to recognize you very rapidly by your behaviour and attitude towards the world, and b) will be able to detect impostors. Don’t worry too much about it. =) If someone comes on as “stimps” and it’s not me, most people can figure that out pretty dern quickly. =)
Anyway, try to have fun and don’t get caught up in this sort of issue too much. If security is a big issue to you, use an irc client that allows you to securely log in (ssh) to the network. If keeping your nick for yourself always is important, never log off. Since that’s sort of not possible for most people unless you have the fatty DSL (she said, chortling), then just don’t worry. IRC is not something that needs the sort of intense security that you’re discussing here, feadan. There’s nothing inherently important going on on IRC – if you were looking for a secure communication method that needed password protection, that could not be read by anyone else, IRC is not the mode of communication you need. =) It’s meant to be a fun environment for communication, and that’s it. It’s not meant to be a commercial, secure environment. So don’t expect it to be, and everything will be great. =)
stimps
[ This Message was edited by: stimps on 2002-01-13 23:38 ]
Thanks Stimps. I really have no experience with the chatroom scene. Having been weaned in the college computer lab environment has made me over-cautious I guess.