An Open Letter to the PRTA Management and the PR Community
Posted: 2015-04-17 21:03
We would like to inform the PR community of the serious transgression by an individual and the PRTA management's failure to recognize and act on this.
The purpose of this thread is to inform the PR community of what has happened but also to point out that we will deal with any similar offences harshly. A line has been crossed and we are hoping that we can leave this mess behind us and use this as an opportunity to start all over.
A member of the PRTA management gained access to a private section of the [NEW] forums, which is shared between the [NEW] community and the clans [KSK] and [3dAC], by social engineering and leaked everything that was posted in there to the PRTA management forums.
On March 31st, a member of the PRTA management used a proxy and an e-mail address matching the identity of the person he wanted to imitate to gain access to the private "Ally Discussion" section in the [NEW] forums. Eventually he was granted access by the [NEW] board administration. We admit this was a mistake from our side. We were simply naive and didn't think anyone would want to exploit our trust like that - we were wrong. On April 15th it was brought to the attention of the [NEW] website administrators that someone was leaking internal communications. We were provided with several screenshots of our private forums within the PRTA forums.
The section the leaker had access to contained idle chat but also plans and preparations for events. The section also lists upcoming map tests, including map files which we guaranteed the mappers to keep private.On the screenshots provided by the whistleblower you could see that someone used the browser search function (Ctrl + F) and searched for "PRTA", the search results were highlighted.
We were shocked by the meticulous nature of these actions. The attacker impersonated a North American member of [3dAC]. Changed the board language, time zone, and used a proxy located in the US.There was no legal way for us to find out who it was without crossing ethical lines.
On April 16th we decided to share all the information we had available at that moment in the "Server Admin Private Forum" of in the PR forums. The post would have been neutral, without any finger pointing and meant as a fair warning to all community leaders and website admins to double check their security settings. We came to that decision in light of the brutal attacks on PRTA this Sunday. [NEW] was targeted by DDoS attacks in the evening hours of Thursday as well which we couldn't count in or out of the whole story at that point. We now believe that those attacks are not connected to these forum leaks.
We were about to post what little we knew in the Server Admin Forums, and we approached PRTA individually to discuss whether they knew anything about this security breach. Four PRTA managers were present during a short meeting in TS. They were kind enough to cross check a few IPs for me but as expected didn't find anything. They said they have neither heard nor seen anything regarding a possible leak in the [NEW] forums.I appreciated their support and left their teamspeak.
Two minutes later I was poked by one of the PRTA managers asking if I could spare some time for further discussion. I rejoined the channel and after that, they said that one of their managers had been leaking information from the [NEW] private section. I asked MrSheneai and Ranzpirat, two [NEW] admins and moderators, to join my discussion with them. They confirmed that they had access to internal information and revealed everything. A member of the PRTA management had been divulging private information in their management forums on a daily basis. He first posted the sensitive information on April 6th; though he had gained access and was able to view the private section as early as April 2nd.
They then revealed that they knew about all the planned map tests, including downloads, teasers, and other events.The individual shared whatever was posted in our forums on a regular basis with the PRTA management. The PRTA managers present at the meeting said they didn't know the information was from a private section. Similarly, they claimed they had only found out about this when I first approached them.There is, however, the possibility that not all members of the PRTA management had been following or were aware of the information posted in a thread called "NEW/3dAC" in the PRTA management section.
During this TS meeting I was also contacted by one of the PRTA managers by PM in an aggressive way and without provocation. It turned out that it was connected to the map test for the Polish Armed Forces which originally should have been organized by PRTA but didn't take place due to several reasons which are not relevant here. PRTA, at that point, could never have known that we would have been running the map test without the leaked information. Shortly before we left, one of the PRTA managers laughed and said "I told you the leak will get leaked."
It is shocking to see that none of the PRTA management had the integrity to contact a representative from any of our communities. The whistleblower has no connection to the PRTA management and will reveal himself by his own volition. We leave it up the PRTA management to reveal who was the one behind gaining access to the private section and leaking the internal information.The fact that the PRTA management only came out with the entire story when we were about to share it is evidence that they only cooperated to mitigate the potential damage to their reputation.
We expect the PRTA management to make a statement in this thread. It is not in the interest of anyone here to cause drama, havoc, or any further harm to the PR community. It is not in our interest to divide this community even further. We would like to use this opportunity to start afresh. We offer more cooperation, communication, and transparency from our side. We are all sitting in the same boat.
We understand that this fault lays with the PRTA managers and is not representative of the PRTA community as a whole. We hope to keep good relations with PRTA members and would like to remind them that they are always welcome on our servers. We are here to talk about this, and find a solution. This will only happen if there is enough cooperation and will from both sides. We offer the PRTA management the chance to communicate and coordinate on all levels, if that is in terms of events, bans, or any other matter. We respect PRTA's role in the community and honestly hope that they are willing to cooperate, moving forward to bridge the gap between our two communities.
We would like to ask everyone to keep this discussion calm and mature.
@R-MODs please remove any offtopic, bashing or trolling.
On behalf of the [NEW] community, the [KSK] clan and the [3dAC] clan,
[NEW] MrSherenai, [KSK] Norby & [3dAC] Curry-Chicken
The purpose of this thread is to inform the PR community of what has happened but also to point out that we will deal with any similar offences harshly. A line has been crossed and we are hoping that we can leave this mess behind us and use this as an opportunity to start all over.
A member of the PRTA management gained access to a private section of the [NEW] forums, which is shared between the [NEW] community and the clans [KSK] and [3dAC], by social engineering and leaked everything that was posted in there to the PRTA management forums.
On March 31st, a member of the PRTA management used a proxy and an e-mail address matching the identity of the person he wanted to imitate to gain access to the private "Ally Discussion" section in the [NEW] forums. Eventually he was granted access by the [NEW] board administration. We admit this was a mistake from our side. We were simply naive and didn't think anyone would want to exploit our trust like that - we were wrong. On April 15th it was brought to the attention of the [NEW] website administrators that someone was leaking internal communications. We were provided with several screenshots of our private forums within the PRTA forums.
The section the leaker had access to contained idle chat but also plans and preparations for events. The section also lists upcoming map tests, including map files which we guaranteed the mappers to keep private.On the screenshots provided by the whistleblower you could see that someone used the browser search function (Ctrl + F) and searched for "PRTA", the search results were highlighted.
We were shocked by the meticulous nature of these actions. The attacker impersonated a North American member of [3dAC]. Changed the board language, time zone, and used a proxy located in the US.There was no legal way for us to find out who it was without crossing ethical lines.
On April 16th we decided to share all the information we had available at that moment in the "Server Admin Private Forum" of in the PR forums. The post would have been neutral, without any finger pointing and meant as a fair warning to all community leaders and website admins to double check their security settings. We came to that decision in light of the brutal attacks on PRTA this Sunday. [NEW] was targeted by DDoS attacks in the evening hours of Thursday as well which we couldn't count in or out of the whole story at that point. We now believe that those attacks are not connected to these forum leaks.
We were about to post what little we knew in the Server Admin Forums, and we approached PRTA individually to discuss whether they knew anything about this security breach. Four PRTA managers were present during a short meeting in TS. They were kind enough to cross check a few IPs for me but as expected didn't find anything. They said they have neither heard nor seen anything regarding a possible leak in the [NEW] forums.I appreciated their support and left their teamspeak.
Two minutes later I was poked by one of the PRTA managers asking if I could spare some time for further discussion. I rejoined the channel and after that, they said that one of their managers had been leaking information from the [NEW] private section. I asked MrSheneai and Ranzpirat, two [NEW] admins and moderators, to join my discussion with them. They confirmed that they had access to internal information and revealed everything. A member of the PRTA management had been divulging private information in their management forums on a daily basis. He first posted the sensitive information on April 6th; though he had gained access and was able to view the private section as early as April 2nd.
They then revealed that they knew about all the planned map tests, including downloads, teasers, and other events.The individual shared whatever was posted in our forums on a regular basis with the PRTA management. The PRTA managers present at the meeting said they didn't know the information was from a private section. Similarly, they claimed they had only found out about this when I first approached them.There is, however, the possibility that not all members of the PRTA management had been following or were aware of the information posted in a thread called "NEW/3dAC" in the PRTA management section.
During this TS meeting I was also contacted by one of the PRTA managers by PM in an aggressive way and without provocation. It turned out that it was connected to the map test for the Polish Armed Forces which originally should have been organized by PRTA but didn't take place due to several reasons which are not relevant here. PRTA, at that point, could never have known that we would have been running the map test without the leaked information. Shortly before we left, one of the PRTA managers laughed and said "I told you the leak will get leaked."
It is shocking to see that none of the PRTA management had the integrity to contact a representative from any of our communities. The whistleblower has no connection to the PRTA management and will reveal himself by his own volition. We leave it up the PRTA management to reveal who was the one behind gaining access to the private section and leaking the internal information.The fact that the PRTA management only came out with the entire story when we were about to share it is evidence that they only cooperated to mitigate the potential damage to their reputation.
We expect the PRTA management to make a statement in this thread. It is not in the interest of anyone here to cause drama, havoc, or any further harm to the PR community. It is not in our interest to divide this community even further. We would like to use this opportunity to start afresh. We offer more cooperation, communication, and transparency from our side. We are all sitting in the same boat.
We understand that this fault lays with the PRTA managers and is not representative of the PRTA community as a whole. We hope to keep good relations with PRTA members and would like to remind them that they are always welcome on our servers. We are here to talk about this, and find a solution. This will only happen if there is enough cooperation and will from both sides. We offer the PRTA management the chance to communicate and coordinate on all levels, if that is in terms of events, bans, or any other matter. We respect PRTA's role in the community and honestly hope that they are willing to cooperate, moving forward to bridge the gap between our two communities.
We would like to ask everyone to keep this discussion calm and mature.
@R-MODs please remove any offtopic, bashing or trolling.
On behalf of the [NEW] community, the [KSK] clan and the [3dAC] clan,
[NEW] MrSherenai, [KSK] Norby & [3dAC] Curry-Chicken