View Full Version : WARNING Mods!!! Accounts getting mixed up via opera mini !!!
.dredd.
25th November 2008, 03:22 AM
Heads up!!
I just opened xda dev in opera mini and I am logged in as a user called dredd?????
not in the same country as this user!!?
I will log in on a desktop browser (firefox) now so i can see if this post is here!
Ive edited his sig just so i can verify that it is fully logged in as another user,
a severe security lapse by opera, or a known bug????
.dredd.
25th November 2008, 03:42 AM
anybody come accross this before?
fex
25th November 2008, 04:14 AM
how bizarre!..:confused:
.dredd.
25th November 2008, 04:19 AM
most odd!
i just logged out and closed opera mini and im still logged in as dredd when i reopened it?
cookies deleted and before i initially opened opera i had just hard reset?
Mikey
25th November 2008, 04:31 AM
most odd!
i just logged out and closed opera mini and im still logged in as dredd when i reopened it?
cookies deleted and before i initially opened opera i had just hard reset?
If you are not dredd, what is your username suppose to be???
pdx77
25th November 2008, 04:38 AM
If you are able to access his account, why are you did you edit his sig and now you are posting from this other person's account? Wouldn't that be against the forum rules as far as gaining access to someone else's account, even if it was just an accident I sure wouldn't be going around posting under his account.
fex
25th November 2008, 04:44 AM
If you are able to access his account, why are you did you edit his sig and now you are posting from this other person's account? Wouldn't that be against the forum rules as far as gaining access to someone else's account, even if it was just an accident I sure wouldn't be going around posting under his account.
I was posting under his to verifyi actually had access.
dont come all high and mighty an go mentioning rules to me.
I was just warning ppl not abusing this fellows account.
Iceman692
25th November 2008, 06:00 AM
this definately has nothing to do with opera unless you would have downloaded opera or a cooked rom from this forum that may have somehow contained his/her log in information.
the only other way this could have happened is an error with the forum servers
jashsu
25th November 2008, 06:14 AM
Opera Mini works via proxy servers, so its possible that their servers sent fex dredd's login state. Just another reason why proxy server browsers suck ass.
pdx77
25th November 2008, 06:24 AM
Opera Mini works via proxy servers, so its possible that their servers sent fex dredd's login state. Just another reason why proxy server browsers suck ass.
Consdering millions of people use Opera Mini, the chances of something like this is quite slim, it's possible I'm sure, but rare. Can a mod verifiy to see if he did indeed post via Opera Mini by verifying the IP address?
.dredd.
25th November 2008, 09:30 AM
Hi
I am the REAL .dredd.
I also experienced the false login using opera mini so it happened not to only one member.
In the past few days I have been logged in accidentally under 3-4 members... today I was wondering seeing Ababrekar's notification for me...:(
fex:
It would have been nicer to give this warning to the forum under your account instead of mine.
fex
25th November 2008, 01:48 PM
still logs me in as dredd if i use opera mini
DaveShaw
25th November 2008, 01:59 PM
I've reported this post to the Site admin to have a look at.
Ta
Dave
Flar
25th November 2008, 02:11 PM
Mostly the ip addresses you guys use are the same, if you're using a proxy that could be the problem. If at all possible could you try to eliminate the proxy?
Best regards,
Flar
Site admin
.dredd.
25th November 2008, 03:15 PM
Mostly the ip addresses you guys use are the same, if you're using a proxy that could be the problem. If at all possible could you try to eliminate the proxy?
Best regards,
Flar
Site admin
Hi Flar!
The REAL .dredd. is here :)))
As I mentioned I also experienced the problem but... in 3 different times I was logged in into 3 different accounts... pls do not ask which ones because I did not care... I only checked the new topics and new devs as always... as if I would have been logged with my own account.
Nevertheless the symptom is strange and should be solved.
I did not touch any settings in my connections and nor in opera mini settings... to tell the truth I do not know how to eliminate proxy in operamini... today morning I logged in without problems with operamini.
The only thing I am angry at is that other user made a forum entry (even a new topic) in the name of mine... abarekar gave me a notification due to this.
Thx
.dredd.
S.V.I
25th November 2008, 05:12 PM
I KNOW WHAT THE PROBLEM IS: You packaged an already synced mini!
The issue happened when I made an update to my rom. I cabbed up the all of the _s0 files after already setting up my mini. syncing it and everything.
It saved my settings.
HOW TO SOLVE:
delete all of the _s0 files and start from scratch. redownload opera mini (signed) and install. fix all of the security things. Take just the newest files ( you can use the explorer on your pc to arange as modified.) copy those for your package.
This version of opera mini has more files. including various skins.
Now the only problem is that you need to get rid of all the versions that have already been uploaded;)
fex
25th November 2008, 11:09 PM
The only thing I am angry at is that other user made a forum entry (even a new topic) in the name of mine... abarekar gave me a notification due to this.
Thx
.dredd.
Cant see why your angry mate I did nothing but inform the mods and site users of the issue.
I could have messed with your account or posted shit under your name which wouldve been fair reason for your anger.
Fex
shadowmike
26th November 2008, 01:56 AM
Cant see why your angry mate I did nothing but inform the mods and site users of the issue.
I could have messed with your account or posted shit under your name which wouldve been fair reason for your anger.
Fex
I can see both sides. I also agree that it would tick me off if someone did it to my account. but at the same time i understand if i was on someones account i would do the same thing.
Thresher
26th November 2008, 02:43 AM
Hey Fex, at this point I do belive the words should enter your stream right now, "I DO understand why you are upset and I never meant to violate your account or sense of community. I understand that my attempt to exemplify the problem and not invalidate your security is at cause. Please understand that my intent was good and that in the future I will notify the community, devs and users from my own account."
Now since the solution has been found and fault can be handed out, the matter of violation of privacy is clearly in the hands of the developer who released the rom with his credentials inside of it.
Your internal fight now Fex is, "Was it ethical to knowingly log in to an account I knew was not mine." Thats all you dude, how would you teach a class full of children to handle the same scenario?
Good find on the problem, great find on the fix, awesome education given to all ROM devs and those who share images and data that touch our own personal data.
samaral
26th November 2008, 05:55 AM
a quick fix to this, without deleting or reinstalling your Opera, would be clearing cookies. and for the account "dredd" to be suspended. at least till this thing clears off. This way, all users will not be able to use the "dredd" account, and be forced to relogin again, therefore eliminating the cookies.
:) my two cents. what you think?
tunppi
26th November 2008, 12:26 PM
well dredd just change your password? isnt that kinda obvious in that situation? old cookies shouldnt let others in with false information after that.
No one else can do it anyway if they dont really know it.
egzthunder1
26th November 2008, 02:04 PM
@fex
I agree with Thresher... this is a matter of internet ethics. We understand (and appreciate) the fact that you discovered this bug. However, the problem lies in the execution of your example. For instance, you could have done the same exact thing (opening th thread, contacting the mods, and so on) from your account. I know that you are obviously not a bad person otherwise you could have wrecked havoc with .dredd.'s account just like you said, but all he is saying is that maybe you should have done it from your own account.
In any case, it was a great discovery on your part. It is good to see that there are still some honest people out there :)
.dredd.
26th November 2008, 03:10 PM
Hi dear all folks!
The REAL .dredd. is here!
I read the discussion and please accept the following:
The malfunction with operamini DOES NOT INVOLVE ONLY MY ACCOUNT!!!!
I also experienced the malfunction seeing that I opened xda-dev and I was logged in as aiwenin or somewhat... next day also opened xda and I was logged in as wiederg or somewhat... it happened to me with one more user name...
Therefore:
I am concerned that the reason of the malfunction is not only that cooked roms contain my user data... I would suspect (without any serious IT background) that xda messed up something. ... maybe I am wrong...
But one thing is sure: not only my account name had been involved.... at least 3 more user account are involved.
I will alter my password soon... let's see if it helps to eliminate the malfunction with my username.
Thank you
Brgds
.dredd.
x-X-x
26th November 2008, 04:16 PM
No, I'm the real dread!;)
pdpdp
26th November 2008, 04:34 PM
http://forum.xda-developers.com/showpost.php?p=2903083&postcount=33
been post long times ago. but nobody care~:D
dsixda
26th November 2008, 08:19 PM
Same problem happens in Facebook.. I didn't get logged in, but it gave me an Italian email address for the user ID (10le....@alice.it). So it's NOT just xda-developers.com.
The problem cleared up after I installed a fresh set of files from Opera Mini 4.2 Beta .
At work we also use proxy servers (just like Opera Mini), and once when I went into ebay.com, it had automatically logged me into someone else's account .... on my OWN computer! That's why I do not save my passwords on browsers that use proxies.
farukb
26th November 2008, 08:58 PM
yeah few days ago i signed in as flar
hehe nah, just kidding:)
RayB
27th November 2008, 04:54 AM
So let me get this straight.
Users are getting pissed off because they themselves allowed their cached credentials to somehow leek into cooked ROMs. If this is somehow true I only see the users themselves to blame and not anyone stumbling across the issue.:rolleyes:
badaas
27th November 2008, 07:58 AM
I'm with fex, sometimes actions speak louder than words.
As we have now seen.
dsixda
27th November 2008, 04:36 PM
So let me get this straight.
Users are getting pissed off because they themselves allowed their cached credentials to somehow leek into cooked ROMs. If this is somehow true I only see the users themselves to blame and not anyone stumbling across the issue.:rolleyes:
I don't think it is their fault. Let's not point fingers.
I saw the .dredd. user ID in the Elf cooked ROM (not the other ROM that was mentioned originally) as well. He just happened to win the "lottery".
crapula512
30th November 2008, 07:46 PM
i have missed this post until now, im using tess 3.1 + SP and at first i was logged on gmail as someone else but dont remeber hes name.
now i have tried facebook and im logged as mattias svensson.
who might be this guy?
xda havenīt give me any false login that im aware of.
rstweb
15th December 2008, 06:55 PM
Please stop discussing why this happens and on which other pages this happens, too. pdpdp has given the answer with a link:
http://forum.xda-developers.com/showpost.php?p=2903083&postcount=33
been post long times ago. but nobody care~:D
the problem is that opera mini uses a proxy server to show pages. so the proxy have the cookies and when you open xda-dev or facebook, the page uses the cookie of the proxy and _not_ of the mobile phone.
only solution is: don't use opera mini for websites with login!!!
Noonski
15th December 2008, 07:52 PM
And now it's my turn to say.
I Am The Law ;)
I hope the Cook has been tracked down and shot (or hopefully informed in a nice gentle manner)
Hope this teaches everyone a lesson.
OperaMini Sucks, everything Mini Sucks.
Except for vehicles, big Vehicles suck more Gas.
Okay done with the fun stuff.
Just be sure to next time:
1. First and formost contact the Site administration through a PM.
You never know how serious the issue might be.
2. Never wilfully log in and post as another user. It's understandable that no harm was meant. But strange things happen in someone's mind once his or her private space has been intruded. Even a compromised Virtual member Login can have effect on how safe someone feels the next time they come online.
3. Contact the Cook or the Developer (in this Case Opera) directly. Starting a post in a place where the cook might never come will not speed the issue up. Luckily, again in this case everyone was lightning fast.
All in all everything went just great, but consider where it could have gone wrong. That's why there's rules of conduct, so we don't have to rely on luck only.
4. If this is indeed because Opera's Proxy is making a mess out of all the page requesting parties. It's a serious flaud. I'm hoping someone thaught of contacting them, pretty curious about their response to this problem if it is theirs. (next to the confirmed incorrect cooked package)
metusmortuus
9th January 2009, 06:10 AM
I think the solution was mentioned above, but just to clarify, this problem only occurs when Opera Mini is pre-installed on the rom. The reason is that Opera asks you to enter a string of random characters upon install, and since this random string became the same for all users of the rom in question, Opera couldn't properly differentiate between unique users. In other words, I don't think there are any problems with Opera Mini when installed from scratch.
vBulletin® v3.8.7, Copyright ©2000-2012, vBulletin Solutions, Inc.