Welcome to Inkbunny...
Allowed ratings
To view member-only content, create an account. ( Hide )
Blackraven2

Do not make your life depend on a single website...

The internet is becoming more and more centralized.

Technically anyone could set up a server, a webpage, or make a data connection to anyone else (if you ignore NAT routers for a second)

But the trend is not peer 2 peer, the trend is going towards centralized portals. Millions of people are dependant on just a hand full of webpages to a degree that their life would be severely impaired if those webpages would go down.

What would you do, if google would go down (or blocked in your country, like in China) taking with it Gmail, search, docs, social connections, youtube, even your precious files you stopre in the cloud, the app store for your phone, ..., ..., ...

What would yo do if Facebook went offline. Or LinkedIn?

That would have a severe impact on the social life of many million individuals. But yet they went into this dependency willingly (granted  there's a tiny bit of peer pressure, too)

It can get worse. If you make a living on-line with your art, you depend on your platform for advertising client interactions, portfolio showcase and messaging.

Your monthy income might depend on the likes of Inkbunny, Deviant Art, Sofurry, or Furaffinity.

Let's looka  bit into the latter example.

Large web platforms have a heritage, and a grown proprietary code base. The larger that gets, the older it gets, the more buggy it becomes. For every thousand lines of code, you can generally expect one hidden undetected security flaw. If you do regular audits and code reviews and put painstaking effort into security it becomes one in ten thousands lines, but from a certain complexity on the bugs are always there. There's always one more. Security critical bugs are found in code that's twenty years old and been open source the whole time!

That's why even sites using an open source content managment system are hacked regularly. Even though thousends of people search through this code to make it more secure, there's also thousands of people searching for flaws they can exploit. And they have to find just one.

FA was hacked using a generic security flaw in a common library, but the attacker downloaded the entire code base and distributed it. It's out there, somewhere, and people can now search for flaws. One person already found a flaw, and used it to delete FA's database, that's why the site went down. Now they are reportedly doing a code audit.

Don't expect it to come back soon. A proper code audit can take weeks. It might be quicker to rewrite everything from scratch. It would definitely be saver to rewrite everything from scratch in a case like this, because you will never find ALL security flaws. It's a task like finding ALL needles in a landfill of used paperclips that are bent into all kinds of shapes (including straight like a needle).

FA will either stay down for a few months, or if it comes back sooner, it will go down again after a relatively short time because they missed a needle, and someone else found it.

But it's not just FA, and it's not just hacks you need to worry about. Changes in ownership, legal troubles, political influence and a million other factors could affect a site, its availability in your country or its availability to you, personally. Sometimes they just change their business model and whatever your most used feature was is now premium only, or discontinued, or "improved" in such a way its now completely unusable.

Sometimes, someone complains about you, and you end up on an admins wrong foot. I'm not even going into FA specifics on this topic. People have had their google and facebook accounts blocked because of unjust complains of others. Their youtube account suspended because of a wrongful copyright claim, lost all their ebooks on amazon because they dared to read them from the wrong country, or gotten their account frozen on paypal because one single client refused to pay.

Half the youtube links I click on, all I get is "this video is not available in your country!"

Did you know that if you try to access your gmail from abroad, google thinks someone is trying to hack the account and won't let you in before you haven't "confirmed your identity" with your cellphone and all sorts of things you might not even be able to?

These things happen. They happen on a daily basis, and they can happen to YOU!

So long story short, heed this wakeup call.

Make sure you stand on more than one leg - be it your emails, social internet, and especially anything you need for your work and income. Make sure you are not dependant on <insert favorite platform here> to get in contact with commission clients or artists, at least get their email as well.

Put your portfolio, or at least some of it on at least two platforms so you can be found and contacted if one goes down.

And if you can, get your own webpage and host your stuff yourself. That way, even if furry porn was outlawed in the US and all the sites went down, yours will still be found, and you can be contacted.
(Let's not forget there's a presidential election this year. And we all know who's a candidate.)

Viewed: 65 times
Added: 7 years, 11 months ago
 
Furlips
7 years, 11 months ago
Well spoken, can I link to this and tell others?

Bunners
Blackraven2
7 years, 11 months ago
Absolutely, please, that's why its there :)
Furlips
7 years, 11 months ago
Thank you, but I thought I'd "break protocol" and ask first. ;-)

Bunners
Furlips
7 years, 11 months ago
Done.

Thank you.

Bunners
soggymaster
7 years, 11 months ago
You're preaching to the choir here, but this is an excellent essay.  Thank you.
Blackraven2
7 years, 11 months ago
Thanks - well, with FA now down the choir might get a few more singers :)
kitsunelegend
7 years, 11 months ago
FA, Inkbunny (dur lol), Sofurry, weasyl, Furrynetwork, Deviantart, facebook, skype, teamspeak, cell phone, three different email accounts, (one yahoo, one gmail, one hotmail), a youtube account, several game forums, steam, and probably a few other places I've forgotten about, are all the places I am currently on and using for content and contact purposes, so I think I may be good XD

I also have the home addresses of some of my friends for snailmail if all else fails (written on post-it notes stuck to the inside of a small lock box), so I can at least stay in contact with them. (that, and my parents live with-in 10 minutes walking distance from me lol)

And if all else fails, I'll invent teleportation to always be able to talk with people who live in other states/countries other than my own. X3

I feel like I have all my bases covered. =P

All that aside though, this is very well thought out and well written. Will probably pass it along to some others I know that probably should spread themselves out more. Thanks for this! =)
AlexReynard
7 years, 11 months ago
Glad you put this up, amigo.

Also, "Half the youtube links I click on, all I get is "this video is not available in your country!"" Have you tried ProxTube? https://proxtube.com/
Blackraven2
7 years, 11 months ago
Of course I do :)   Doesn't work all the time though.
Alfador
7 years, 11 months ago
Actually Gmail will force me to authenticate if I'm on ANY device I haven't logged in from before--even if it's in the same town I live in. Because I told them to. Because I happen to think it's a far higher probability that someone will try to compromise my account than that Google will go under or be blocked without enough notice time to retrieve all documents important to me.
Blackraven2
7 years, 11 months ago
You need to be responsible. Using the safety feature they offer is part of that. But  you need to have a plan B if google decides for whatever reason - justified or not - to suspend your account. "Banned from google" is a thing that can happen, you can google it ;)

Have you ever tried to reset your google password? I tried it once, I got presented with a list of questions by google, including not only the safety questions and personal details you put when you create the account the first time but also such things as "when did you last log in" "when did you first create your account" and all sorts of things where they wanted both day, month and year - and I simply didn't know. I have my account for a few years, but since when exactly? Google of course has that on file. You need to get a certain percentage of those questions correct. Google doesn't tell you which were answered correctly and which weren't, it only tells you "sorry, that's not enough"

Mind you, if you have two factor authentication, it might simply send you an SMS instead. But what if your phone was stolen and you don't can't receive those anymore?

Security features are good as long as you can control them and you know in advance what you need. With google that isn't the always the case. And they change those things on a whim, too. (Remember when you suddenly needed a google+ account to use youtube, and they urged you to create a google+ account, for which they also demanded a real name? Luckily they stopped doing that)

GreenReaper
7 years, 11 months ago
" even if furry porn was outlawed in the US and all the sites went down…
Inkbunny is actually hosted in the Netherlands, although we do have caches in the USA - so they'd have to go to some extra effort to block us (and even then, it'd probably be accessible via Tor).

Your general point is right on, though. :-)
Blackraven2
7 years, 11 months ago
Once again I wish I could fav comments :-)  That setup is really reassuring!

You guys know what you are doing, and I trust you a whole lot more that a great number of other sites.

I guess I should at some point do another sponsorship (which would be easier if Paypal would not refuse my credit card and wont revalidate my account)

But until then I'll just hereby give you a virtual hug for the great work you're doing :-) Pass it on to the rest of the staff :-)

GreenReaper
7 years, 11 months ago
Will do! And we take lots of options, although some are tricky to do in certain countries. :-)
Blackraven2
7 years, 11 months ago
FA is currently urging for everyone to change their password, as well as changing the password on every other site you might have used the same password.

That's a clear indication that FA's user base was leaked or is suspected to have been leaked including login details.

I don't know if FA stored its passwords hashed and salted individually, or with a global salt, or with no salt or even plain. But either way it would be wise to heed this advice.

If you get more spam to the email you used for your FA address in the near future, you know why ;)
foxboyprower
7 years, 10 months ago
I got locked out of my account for a month because of this. And yes, that's why I was so inactive and just got around to reading this. I just gained access to my account a few days ago.
Blackraven2
7 years, 11 months ago
"
FA will either stay down for a few months, or if it comes back sooner, it will go down again after a relatively short time because they missed a needle, and someone else found it.


...
"
Administrator notice:
We have temporarily put the site into Read Only mode while we work on implementing additional security measures. We have just learned the attackers have access to personal user data, such as encrypted passwords and email addresses.


Sometimes I hate when I'm right. Especially when its that obvious.
foxboyprower
7 years, 10 months ago
This makes the internet scary. =(
New Comment:
Move reply box to top
Log in or create an account to comment.