information

7.0 Release Security Notice

10.01.2002 - Please read through this important announcement!

Changes for:
FREE Communities | FREE User Accounts | Security Changes FAQ


tack A Letter From Our Founder

Dear ezboard members,

We are pleased to announce the release of ezboard version 7.0 early this month. Version 7.0 contains a number of important elements, three of which will affect users and communities across the entire network. We want to let you know in advance of the release about these changes.

control centerVersion 7.0 will introduce a new presentation framework using webstandards (XHTML and CSS positioning). You'll see these changes initially in the control center (see terminology changes) and user profiles and eventually in the forum areas. This new framework will allow the highest degree of customization ever possible on a message board and facilitate the trading of skins/themes/etc. This new framework may require you to update your browser. Please read how this might affect you.

Other major changes in 7.0 are related to security. The safety and security of your accounts and communities is of utmost importance to us. In order to tighten security and provide an enjoyable and safe experience for all, we are introducing new limitations in areas where exploits have been used to breach security – custom signatures and personal profiles for users, and advanced customization for communities. These changes will primarily affect the FREE communities and users on those FREE communities. ezSupporters and GOLD communities are not affected. FREE users and FREE communities should read how this will affect you.

In a related development, we will be introducing user Profile Skinning. While this feature will create great flexibility in designing and sharing user profiles, it comes with a price. ezSupporters, if you currently have a profile customization CSS “hack” in your user profile, it will no longer function in Version 7.0. You can get complete details here.

Lastly, on behalf of the entire ezboard team, I would like to thank you for your continued support. What started on a dialup and modem for a small group of friends has grown to global proportions. Today, ezboard is one of the largest sites in the world (top 100!) with millions of people using ezboard every day to connect with others. However, we at ezboard feel we are just getting started. By combining the talents, convictions and passions of ALL of us, we know ezboard will continue to have a positive impact on the lives of many people today and tomorrow.

Best regards,
Vanchau Nguyen
Founder & CEO


Detail of Security Changes

The following changes are being made in order to tighten the security across the ezboard network. Over the years we have identified who and what kind of attacks are done. The changes below will remove the tools that are used in attacks. Thank you for your cooperation and understanding.

Changes for FREE/Trial Communities

Changes for FREE User Accounts

Changes for ezSupporter Accounts

Changes for Gold Communities

top top


Security Changes FAQ

Why are GOLD communities and ezSupporters able to have potentially dangerous features?

In our experience, over 99% of attacks come from FREE communities and users, not subscribing communities and members. We believe the biggest reason is that a person who pays for their service does not want to risk losing their service by causing trouble for others. However, If any Gold Community or ezSupporter is found exploiting these features by adding malicious code, their community and/or account will be locked down immediately and no refund will be given. There are no exceptions. Please see our Terms Of Use for details

What about people/communities who use JavaScript to have things like clocks or counters?

Since it is impossible to distinguish safe JavaScript code from unsafe JavaScript code, we must disable all JavaScript. However, we are evaluating ways to provide these types of services through ezboard (i.e., we provide the code from our servers for use).

I'm an ezSupporter and have taken advantage of the CSS "hack" to customize the look and feel of my profile. What will happen to my current CSS customization when the changes take place?

With the 7.0 release CSS profile customization will become a fully supported ezboard feature. Unfortunately, this means that all previous"hacks" will not work with the new system. While we regret this inconvenience to our paying customers, our new Profile Skinning feature will allow for almost unlimited customization of your profile that was not available with the "hack". More information can be found at the Profile Skin Trading forum.

Why are you only allowing ezcodes in Custom Signatures for Free Users?

To many simple HTML coding may seem benign, however in the wrong hands it can and has posed serious security risks for ezboard communities. We have removed HTML capability from Free Users because that's where the problem arises. However, any ezSupporter found abusing their HTML signature priviliges will be immediately banned - no refund will be given.

How will this move from HTML to ezcodes affect my current HTML signature?

For the vast majority of our users, all signature coding that was in HTML can now be done with ezcodes. All you will need to do is simply recode it with ezcodes instead of HTML. Click here for a link to the ezcodes tutorial.

top top