Win uses cookies necessary for site functionality, as well as for personalization. By using this site, you agree to our use of cookies as described in our Privacy Policy.
Its NOT enough to say 'just click on only approved sites linked on the sidebar of https://communities.win/'
People will likely be linking to other .win domains in comment sections. Every time you click on those links it may be a fake domain. Would you notice if I linked http://kotakulnaction.win instead of http://kotakuinaction.win ?
ADMINS: please create filters to ban ALL .win links that are not approved memebrs of the win network to prevent phishing attacks
I think one of the issues with that is that its less appealing to sites to move then, its less identifiable or appealing potentially, to be under the td.win main domain (at least if this place is going to become really diverse). Unless they do something like communities.win/w/kotakuinaction etc. That could be an option. but obviously having their name as the main domain is appealing, but that also makes it susceptible to domain squatters too.
Well, communities.win with /w/community or /c/community alias forwarding to an actual host would be better, methinks. That way we stay decentralized and together at the same time.
We're already not really decentralized by having a shared user database. Wouldn't be surprised if the domain names were pointed at the same physical site.
Also, I'm a bit new around here I've only had my account for about a month, and lurked for a few weeks prior, so I apologize if this is well know info; but, how do we go about supporting this place? I've tried turning off my ad blocker and I don't see any ads.
With all the new traffic, and now new communities, I'd imagine the cost of hosting will be going up.
For a start, it should be obvious with no more effort than a mouseover somewhere what the complete list of authorized .WIN Trump-supporter-affiliated domains are. I agree with the urgency. There are a number of proactive steps we must take immediately that any security-minded admin will think of.
You would have to have something to scrape all the comments and delete anything with an non authorized .win link. This also drives for a master .win page that would be a hub for browsing .win sites. Something where you can basically land, setup favorite .win pages, and then jump from there to your pages.
Grab all of the .win domains with mistakes in it like thedahnald.win, thedonnie.win, therealdonald.win, thedonaId.win (the letter L is replaced with an capital I in this one) etc, and have all of them be redirected to this one.
Lads, this is more of a flag in the sand post than self promotion, KAGGER.win is a dedicated Pro-America, Pro-GEOTUS page but it’s outside the .win network. We have been live for months, and we are here to party!
Why keep the same password across all the domains? That is a password leak waiting to happen.
Either create a single "authorization point" for all the websites or have them all manage their own credentials. Allowing all of them to ask for same password is a problem waiting to happen.
Implement an oauth where there is a single authorization point which will give finite time tokens that can be checked by all the websites by crosschecking with the authorization point.
I can volunteer some coding time, in 2 week from now, if needed.
Its NOT enough to say 'just click on only approved sites linked on the sidebar of https://communities.win/'
People will likely be linking to other .win domains in comment sections. Every time you click on those links it may be a fake domain. Would you notice if I linked http://kotakulnaction.win instead of http://kotakuinaction.win ?
ADMINS: please create filters to ban ALL .win links that are not approved memebrs of the win network to prevent phishing attacks
CTR / ShareBlue lives for this kind of thing, especially in election year.
As a temp measure, this is probably a must. Just whitelist only the official .win communities
I see your point.
I had to enhance 5x to see the difference. Good call!!!
I have been noticing some of the comments lately. They are here i believe.
I've been at war with those motherfukers all day today
New feature idea: bricks on user page for each shill we deport successfully
Fuck yes
I love this.
I crown thee deporter in chief
Have three internet crowns 👑👑👑
yeah it’s been pretty obvious
true. they have been here since January this year.
Oh definitely
I strongly advocate using thedonald.win as the top-level domain and letting sub-communities have subdomains.
Yeah I really don't think having so many separate domains is good for user friendliness and security
I think one of the issues with that is that its less appealing to sites to move then, its less identifiable or appealing potentially, to be under the td.win main domain (at least if this place is going to become really diverse). Unless they do something like communities.win/w/kotakuinaction etc. That could be an option. but obviously having their name as the main domain is appealing, but that also makes it susceptible to domain squatters too.
Agree, that's a good option. But I sort of like the idea that everyone has to use "the Donald".....
They should make an overall new domain. something like freedom.win/dom_name
Other suggestions 1776.win altright.win (tongue in cheek name just for the triggering purposes and salt mining)
It would be awesome if we could then have a front page in aggregate with all of the communities we're subscribed to. A guy can dream!
Well, communities.win with /w/community or /c/community alias forwarding to an actual host would be better, methinks. That way we stay decentralized and together at the same time.
No way. That’s begging for leftist infiltration. Decentralisation is the future.
We're already not really decentralized by having a shared user database. Wouldn't be surprised if the domain names were pointed at the same physical site.
100% Agree.
Also, I'm a bit new around here I've only had my account for about a month, and lurked for a few weeks prior, so I apologize if this is well know info; but, how do we go about supporting this place? I've tried turning off my ad blocker and I don't see any ads.
With all the new traffic, and now new communities, I'd imagine the cost of hosting will be going up.
Financed by government black book budget or Trump family money maybe?
I’ll donate if mods need help
I never even donate to Wikipedia or anything but I'd gladly throw money as this site. It's the only thing keeping me sane.
Might should have thought about messaging the moderators about this instead of making a post and telling the world about it
Anyone with the skills to pull it off already know it's an issue.
I get that but still..
For a start, it should be obvious with no more effort than a mouseover somewhere what the complete list of authorized .WIN Trump-supporter-affiliated domains are. I agree with the urgency. There are a number of proactive steps we must take immediately that any security-minded admin will think of.
As it grows it’ll be impossible to keep track
Yeah using a multi top level domain approach is problematic.
They should just stick to /r urls like the Chinese site...
Should have just opened them as sub domains from a trusted .win domain.
bumperino..
don't click on links.
Everything contained on this site. I'd like to be able to combine my feeds.
2FA, but for the love of god DON'T ASK FOR ANYONE'S PHONE NUMBER!!!
One solution is to not give a shit.
You would have to have something to scrape all the comments and delete anything with an non authorized .win link. This also drives for a master .win page that would be a hub for browsing .win sites. Something where you can basically land, setup favorite .win pages, and then jump from there to your pages.
Grab all of the .win domains with mistakes in it like thedahnald.win, thedonnie.win, therealdonald.win, thedonaId.win (the letter L is replaced with an capital I in this one) etc, and have all of them be redirected to this one.
I've been away for a few hours, do we have sub-wins now? I opened the side bar and I don't see them?
https://communities.win/
Lads, this is more of a flag in the sand post than self promotion, KAGGER.win is a dedicated Pro-America, Pro-GEOTUS page but it’s outside the .win network. We have been live for months, and we are here to party!
If T_D wants a party page, we are ready to roll!
I tried to message the mods for help. No response...
Not sure why they didn't just go /t/kotakuinaction. I'm sure they have good reason. But something at least.
They could buy up all domain names that have similar misspelling to thedonald
Why keep the same password across all the domains? That is a password leak waiting to happen.
Either create a single "authorization point" for all the websites or have them all manage their own credentials. Allowing all of them to ask for same password is a problem waiting to happen.
Implement an oauth where there is a single authorization point which will give finite time tokens that can be checked by all the websites by crosschecking with the authorization point.
I can volunteer some coding time, in 2 week from now, if needed.