PDA

View Full Version : Are CAMRA in more S**t than they're letting on?



Mobyduck
23-07-2014, 20:07
After being hacked over a week ago the main CAMRA website (http://camra.org.uk/) with this explanation (http://camra.cmail2.com/t/ViewEmail/j/01CDBD9D4C4495D2/4D62911CA501BDC96A4D3D471B02C3D7) (not sure if non members can see this), it remains in maintenance mode, none of the temporary links seem to work and I can't log in to their forum (not a major disaster). Are they just being extra careful , incompetent, or has more than the cat been let out of the bag!

Quinno
23-07-2014, 20:19
After being hacked over a week ago the main CAMRA website (http://camra.org.uk/) with this explanation (http://camra.cmail2.com/t/ViewEmail/j/01CDBD9D4C4495D2/4D62911CA501BDC96A4D3D471B02C3D7) (not sure if non members can see this), it remains in maintenance mode, none of the temporary links seem to work and I can't log in to their forum (not a major disaster). Are they just being extra careful , incompetent, or has more than the cat been let out of the bag!

It was a pretty serious hack but at this point (so far as my inside source tells me) there's no evidence of sensitive details having been accessed.

Pubsignman
23-07-2014, 20:55
Does this explain why I can't amend my beer scores on WhatPub? (I accidentally scored a beer at JJ Moons in Hornchurch, when I meant to score a beer at JJ Moons in Tooting and now I can't seem to correct it)

Quinno
23-07-2014, 21:13
Does this explain why I can't amend my beer scores on WhatPub? (I accidentally scored a beer at JJ Moons in Hornchurch, when I meant to score a beer at JJ Moons in Tooting and now I can't seem to correct it)

correct. No logins are working.

ETA
23-07-2014, 21:19
CAMRA has, like many large organisations, become a victim of its own success. It has become big enough to create a large headquarters (or, as our friends across the pond would call it, 'self-licking lollipop') and has created niches for the under-competeant to hide in.

It is also diverse, so while most grassroots members have the same ideals, there are differences in local policies, customs and practices which cannot be easily accommodated by a centralised governing body which has little institutional (as opposed to individual) understanding of its members (think Brussels here).

But whatever its flaws, it is currently the only game in town, so while we can all occasionally try to find alternatives, the best means of trying to improve it is to join and replace the deadwood with enthusiasm, fight the rot from within and try not to get sucked into the medioćrity. Or, if you can't beat them, join them.

Personally, I try to avoid the politics and just drink beer with my mates.

gillhalfpint
23-07-2014, 21:48
I haven't been on the main site, but have been scoring on Whatpub daily without problems.

Pubsignman
23-07-2014, 22:03
correct. No logins are working.

Just tried again. I can still enter new beer scores so must be logged in, I just can't edit the one I entered incorrectly. :confused:

Quinno
23-07-2014, 22:37
Just tried again. I can still enter new beer scores so must be logged in, I just can't edit the one I entered incorrectly. :confused:

Hmmm, so can I but I can't get into Pubzilla (the back-end database). All most odd.

oldboots
24-07-2014, 07:03
Hmmm, so can I but I can't get into Pubzilla (the back-end database). All most odd.

Apparently there is a workaround in place that allows access to the scoring on WhatPub but the rest has been left until the IT supplier sorts things out.

Q. are you not on the Yahoo groups for Whatpub and Pubzilla?

Dave M
24-07-2014, 09:35
It does sound like they are sensibly trying to make sure they know what led to the hack and to protect against it before bringing everything back up. As it was a server hack it is entirely possible that it wasn't even targeting CAMRA in any way, more likely just spammers trying to take control of a server.

The one thing that has always bothered me from a security point of view is the fact that to log in (at least when I was a member a few years back) you just needed your membership ID and your default password was your postcode. That means that if you know a members postcode you can have a fairly easy stab at getting into their account - I'd guess at most 7 hours to brute force it without arousing much suspicion.