From the main drugslist developer: I'm sorry and it shouldn't have happened.

Hi everyone,

I feel the need to come on reddit and make a public apology on behalf on drugslist. When technical questions are asked, I'm the one giving the answers to our drugslist admin.

I want to apologize to the_avid, Magnus05, and anyone else I was rude to. I was an idiot, and I shouldn't have become so defensive about my careless oversight. I should have responded in a collegial, gracious, and respectable manner to people's concerns. But, because I was embarrassed that I had such a stupid oversight, I reacted poorly and was rude. I do appreciate the goodwill nature of this community, I fucked up and I apologize.

It was potentially a serious bug and was a stupid oversight. Thankfully nothing serious happened as a result (a few unapproved user accounts were created), and the issues were correctly immediately after being pointed. Technically speaking, we weren't using prepared statements consistently (shouldn't have happened), but everything is now uniform.

We're having a second security team look over our work and perform a blackbox pen test on a mirrored, userless version of the site. In the spirit of being as transparent as possible, we will release the results.

I apologize again for my arrogant response, and we do appreciate when users report bugs. It was my fault for acting childishly and again, I would like to apologize to the_avid and Mangus05.

-dl lead developer


Comments


[12 Points] None:

[deleted]


[10 Points] None:

So far, you've handled it poorly but admitted to it. Let's see the pen testing results and see if your going to suffer through the tough times. Everyone else has hauled ass.

Are you going to follow the path of TM, SMP, and countless others?

Or you going to take the difficult path? Only one has so far, backopy. That man could open a market tomorrow and EVERYONE would come running. He got hacked a lots like 200BTC. This wasn't the first security issue he had either.

Comes down to, you got sands or not?

I'm not pulling listings.


[4 Points] Bagnag:

Too many markets already, starting another one (that already has trouble) is like saying "hey, everyone put some coins in this site, so i can shut it down and steal them like the other sites"


[5 Points] pronger:

Are you the one responsible for releasing your code into production?


[3 Points] HackAway12:

i think that a post from /u/drugslist confirming that you are indeed the developer would be appropriate :)


[3 Points] None:

[deleted]


[1 Points] None:

I forgive you. And still trust you more than SR2.0 or Pandora.