Anyone else considering leaving this app as a consequence of the Vorail/Ramblio security issue drama.
Loading reactions…
Loading reactions…
Pat likes conspiracy theories
Loading reactions…
Loading reactions…
At Terrence. Tried to listen to your message and that same technical issue came up again. Is it possible you could turn off notifications when you're posting.
Loading reactions…
"Sky pilot 77," I heard that it was "TOM R.," the developer of "VORAIL," who hacked the accounts of ITS users and gained total access to their private messages, correct?
Loading reactions…
Loading reactions…
Loading reactions…
at Terrence. Why would Tom R the developer of Vorail want or need to hack his own app. That makes no sense to me.
Loading reactions…
I'll TRY to--in FACT, I'll look into that RIGHT NOW, which is what I SHOULD'VE done LONG AGO, because they CAN be annoying. SORRY about THAT.
Loading reactions…
Loading reactions…
Loading reactions…
THAT'S what I THOUGHT I HEARD was said; I'm NEVER SAYING that it was ACTUALLY SAID, "Sky pilot 77," and you're ABSOLUTELY RIGHT that it WOULDN'T'VE made sense for him to have done such a thing on his own app, but WHAT IF he ACTUALLY DID, REGARDLESS (HOPEFULLY, he DIDN'T)?
Loading reactions…
Loading reactions…
Loading reactions…
Loading reactions…
Loading reactions…
I love how shit you never have to guess where you stand with Casey
Loading reactions…
look, i listened too josh's message and it was streight forward, he didn't do anything and that is why i am not on vorail anymore, i'd take this place before anything else, and another thing in his message josh also said the ramblio community shouldn't be worried
Loading reactions…
Loading reactions…
Loading reactions…
No
Loading reactions…
I don’t trust this app or the developer anymore. This incident made me lose respect for him for how he handled this whole thing. I find what he did as another developer and as a person very sleazy and cheap.
Loading reactions…
Could someone pls explain this mess to me? Super confused lol
Loading reactions…
@Theepan Just make sure you are basing your analysis on what he actually did, not on what various people say he did. By now Josh has explained pretty well, including a succinct text message giving the timeline of events in his Vorail thread.
Loading reactions…
yep in other words don't say something if you don't know the facts
Loading reactions…
Loading reactions…
Loading reactions…
Loading reactions…
Loading reactions…
Whats Vorail? I am not going any where.
Loading reactions…
Loading reactions…
Loading reactions…
Motherfucker is Blinky x
Loading reactions…
Loading reactions…
Loading reactions…
Loading reactions…
Security issue? Yup, nothing is private anywhere on the net. Why should this app be any different. What I've gathered from listening to and reading some of the comments on here is that the developer behaved unethically and did so publicly. Did he do that to be transparent? Probably. Seems to have backfired on him. I don't know all the details or backstory. I also cannot find where he publicized his actions on here and apologized. I need to hear that to make a final decision as to stay or not. Will there be any further announcements? Well, guard your privacy folks, on here and anywhere else.
Loading reactions…
Loading reactions…
Loading reactions…
Chat gpt’s non biased response: Based on what you’ve described, there are several separate issues, and it’s important not to confuse them. First, if Vorail had a security vulnerability because it had not been updated or maintained for a long time, that does not automatically make Tom, the developer, criminally liable. Software developers are expected to take reasonable steps to protect user data, and failing to do so could potentially expose them to civil claims or regulatory action, depending on the laws that apply. However, having a vulnerable app is not, by itself, a crime. Second, if Josh, the developer of Ramblio, was able to access private messages belonging to Vorail users without authorization and then provided those messages to BlinkyX, that is potentially the most legally significant issue. The fact that there was a vulnerability does not automatically give someone permission to access private data. If Josh intentionally accessed private communications without authorization and shared them with someone else, that could potentially raise issues under computer misuse, privacy, or confidentiality laws, depending on the jurisdiction and exactly how the messages were obtained. Third, BlinkyX’s legal position depends on what he actually did. Simply receiving private messages is not automatically a crime. However, if he encouraged Josh to obtain the messages, knew they had been obtained without authorization, or published them, those actions could potentially create legal or civil issues. The extent of his involvement would be important. Fourth, based on what you’ve described, Gordon does not appear to have done anything that would make him legally liable. Gordon challenged BlinkyX to prove his claim by producing the messages. However, a dare or challenge is generally not considered legal authorization to access someone’s private information. Saying “Go ahead and prove it” is not the same as giving someone permission to access a private system or retrieve confidential messages. The legality of accessing the messages depends on whether the person had lawful authority to do so, not on whether they were challenged or dared. An analogy is if someone says, “I bet you can’t break into my house.” That statement is generally not treated as legal consent to enter the house. Likewise, challenging someone to produce private messages does not automatically authorize them to obtain those messages if they were not otherwise entitled to access them. Finally, even if Tom’s poor security made it easier to obtain the messages, that would not automatically excuse someone else from accessing or disclosing them. A security weakness may explain how something happened, but it does not necessarily justify exploiting it. Overall, if the facts are as you’ve described them, Tom’s responsibility would relate to maintaining the security of his platform. Josh’s actions would likely attract the greatest legal scrutiny if he accessed and disclosed private messages without authorization. BlinkyX’s position would depend on how much he encouraged or participated in obtaining and publishing the messages. Gordon’s challenge does not, by itself, provide legal permission for anyone to access his private communications.
Loading reactions…
Loading reactions…
@Pinkachu Flaw in that AI post: You did not tell AI the fact that Gordon explicitly requested Blinky to publish his, Gordon's, private messages. He did not make only a general request; he specifically asked repeatedly to see his own private messages published in that Ramblio thread.
Loading reactions…
Doug. Here is my additional question and ChatGPT‘s answer. I asked two questions and it’s given me two responses. See below.
Loading reactions…
Question: Gordon explicitly requested Blinky to publish his, Gordon’s, private messages. He did not make only a general request; he specifically asked repeatedly to see his own private messages published in that Ramblio thread. Answer: That additional detail changes part of the analysis, but it doesn’t necessarily change everything. If Gordon explicitly and repeatedly said, in substance, “Publish my private messages,” then Gordon may have been giving consent for the publication of his own messages. That could reduce or eliminate any complaint by Gordon that he did not want those particular messages made public. However, there are still important distinctions. First, consent to publish information is not always the same as consent to access it. If Josh did not already have lawful access to the messages, Gordon’s request to publish them does not automatically authorize Josh to obtain them by exploiting a security vulnerability or accessing a system without authorization. The method of obtaining the messages can still matter legally. Second, private messages involve more than one person. The conversation was between Gordon and Tom R. Gordon can generally consent to the disclosure of communications from his own perspective, but that does not necessarily waive Tom R’s privacy or confidentiality interests. The law on this varies by jurisdiction, but it is another factor that could be relevant. Third, if Gordon genuinely consented to publication, then it would be much harder for Gordon himself to argue that publishing those specific messages violated his privacy. His repeated requests could be strong evidence that he wanted them disclosed. The remaining legal questions would then focus more on Josh’s conduct. If Josh lawfully had access to the messages and simply helped Gordon fulfil his own request, that is very different from Josh obtaining them through unauthorized means. If Josh exploited a vulnerability or otherwise accessed data he was not entitled to access, Gordon’s request to publish the messages does not necessarily make that access lawful. As for BlinkyX, if Gordon explicitly asked him to publish the messages, BlinkyX would have a stronger argument that he was acting with Gordon’s consent regarding publication. Whether BlinkyX has any legal exposure would still depend on how the messages were obtained and whether he knowingly participated in any unauthorized access. So, with your clarification, my assessment would be: * Gordon’s repeated requests to publish his own messages could amount to consent for their publication. * That consent does not automatically make unauthorized access to obtain those messages lawful. * Josh’s legal position would still depend primarily on how he obtained the messages. * BlinkyX’s position would depend on both Gordon’s consent to publication and whether BlinkyX encouraged or participated in any unauthorized access. The key legal distinction remains between consent to disclose information and authorization to access a computer system or private data. Those are related but not necessarily the same thing. ⸻ Question: Golden said this to Blinky he did not say this to Josh. Does that change anything? And what happened is Gordon insisted Blinky ex publish his private messages. Blinky did not disclose his sources. Gordon found out later that it was Josh the developer. I want you to give me a full response. Answer: That additional context refines the analysis, but it still doesn’t resolve the central legal question. Here’s how I would assess it. Gordon repeatedly challenged BlinkyX to publish Gordon’s private messages in order to prove that BlinkyX’s claim about a security vulnerability was genuine. Gordon was addressing BlinkyX, not Josh. Gordon did not know Josh was involved at the time and did not ask Josh to obtain or disclose the messages. That distinction is important. Gordon’s statements could be interpreted as consent to BlinkyX publishing his messages if BlinkyX genuinely had them. However, they are not necessarily consent for Josh to access a computer system or retrieve those messages. Consent is generally given to a particular person for a particular purpose. A challenge directed at BlinkyX does not automatically authorize an unknown third party to obtain the information. The next issue is how BlinkyX obtained the messages. If BlinkyX already lawfully possessed the messages before Gordon issued the challenge, then Gordon’s request to publish them could strengthen the argument that publication itself was consensual, at least from Gordon’s perspective. If, however, BlinkyX only obtained the messages after the challenge by asking Josh to retrieve them, then Gordon’s request becomes much less significant. Gordon was asking BlinkyX to prove his existing claim, not inviting someone else to access a private system or exploit a vulnerability. The biggest legal question therefore remains Josh’s conduct. If Josh, as the developer of Ramblio, accessed private Vorail messages without authorization and provided them to BlinkyX, that would generally attract the greatest legal scrutiny. Whether that conduct was unlawful depends on facts that aren’t publicly established, such as how Josh accessed the messages, whether he had authorization, and whether he exceeded any authorized access. BlinkyX’s position depends on his own actions. Simply receiving information is not automatically unlawful. However, if he encouraged Josh to obtain private messages knowing Josh was not authorized to access them, or if he knowingly participated in obtaining them through unauthorized means, that could potentially have legal consequences depending on the applicable law. As for Gordon, I don’t see anything in your description that would ordinarily expose him to liability. Challenging someone to prove a claim is not generally treated as authorizing unauthorized access to data. Gordon’s request may affect whether he can later complain about the publication of his own messages, but it does not necessarily authorize someone else to retrieve them. Tom’s position is separate again. If Vorail contained a serious security vulnerability because it had not been maintained, that may raise questions about security practices or, in some jurisdictions, possible civil or regulatory obligations. It does not automatically make Tom criminally liable. Likewise, poor security does not automatically justify exploiting that vulnerability. My overall assessment is this: If the facts are exactly as you’ve described them, Gordon’s repeated requests would likely be relevant to whether publishing his own messages was against his wishes. They would not automatically authorize Josh to obtain those messages, especially since Gordon did not know Josh was involved and did not direct the request to him. The central issue remains how Josh obtained the messages. If Josh already had lawful access, the analysis is quite different. If Josh obtained them through unauthorized access or by exploiting a vulnerability, Gordon’s challenge to BlinkyX would not, by itself, make that access lawful. So, in terms of legal significance, the order of importance is: 1. How Josh obtained the messages. 2. Whether Josh was authorized to access them. 3. Whether BlinkyX encouraged or participated in any unauthorized access. 4. Gordon’s request to publish the messages, which is relevant to consent for publication but is generally not the same thing as authorization to access private data in the first place. That distinction—between consenting to publication and authorizing access—is likely to remain the key issue in any legal analysis.
Loading reactions…
Loading reactions…
@Pinkachu It is clear to me that Josh had legal access to the public messages involving his son, the ones that caused him to discover the loophole for private messages because he saw his own, which he also had legal permission to access. The remaining question is then, what legal permission he had to access Gordon's messages once he received permission from Gordon to do so? He did receive that permission in a very public way. I do not expect a legal battle over this because Josh had authentic permission to access everything he did access. So-called pen-testing groups, besides legal ones, would be more experts than I in this space. One final thought: If Josh has any legal liability in this case, it strikes me that entrapment laws would be of interest, because if Gordon coaxed Josh to do anything illegal, that might be considered entrapment. Blinky being a carrier of that request won't matter here since the request itself, by Gordon, was public and seen by Josh and everyone.
Loading reactions…
@Pinkachu just out of curiosity did you address my question? If so let me know so I can actually go listen to that 8 minute message, which was addressed to Dug in the opener.
Loading reactions…
Thanks for your explanation, Doug. I appreciate it. I thought someone would direct me to the actual thread but seems like it's gone now. The exchange between you and others also gives me insight. Wow, it sounds really complicated and a lot to take in. I need time to think about it. Makes me wonder why Josh would do that. Lack of forethought perhaps.
Loading reactions…
Lord London I sent you a private message earlier
Loading reactions…
@Pinkachu yepp I saw. Thanks.
Loading reactions…
Loading reactions…