CouchSurfing password security vulnerability

Warning: If you get a username / password pop up on CouchSurfing.org, click cancel, do not enter your username and password except on the CouchSurfing login page.

As of right now, I’m seeing this CSS file included on all CouchSurfing.org pages. That file links to this image. That image returns a 401 authorisation denied error. That in turn causes the browser to request a username and password, the realm is given as “CS”. If a user enters their CouchSurfing username and password, that data will be submitted to functionalfreelance.com.

This is a serious security issues as many users are likely to enter their passwords without realising what’s going on.

As far as I can tell from a scan of the whois data and dns records, there is no connection between couchsurfing.org and functionalfreelance.com. It seems likely to me that this is a hack of some sort, either deliberate or accidental. I hope accidental. Either way, this is a significant issue and needs immediate resolution by CS Inc. I have notified Casey Fenton, Jim Stone and Chris Burley directly of this issue.

K2 theme upgrade and threaded comments

I’ve just installed K2 RC8. Previously we were using K2 RC6. I’ve also enabled threaded comments with the default options. So threads go up to 5 levels deep. Any of the admins on this site can change that setting if a consensus feels that it was a mistake. You’ll see new “reply” buttons underneath each comment. That allows you to reply specifically in response to a single comment, like some forum software.

Two measures

“And what is the big deal about CS and its LT?” Two measures, for example. The head of the Ambassadors has two extremely serious negative references for sexual harassment (of former Global Ambassadors) is promoted into the Leadership team.

While someone else’s profile is merely deleted for creating another profile to overcome the issues with the CS group system.

Announcement: Couchwiki.org

It’s been in the pipeline for a while. In fact, I should have done this in 2006 ;) Still, now it’s 2009 and I’m happy to hereby announce Couchwiki.org:

“WikiCouch is open to anyone and everyone. It is in keeping with the philosophy of inclusion and open hospitality. We believe in decentralized control, self-moderation and that everyone has something valuable to contribute.”

* Available under the Creative Commons ShareAlike Attribution license.
* Open for editing to anyone. You don’t have to log in – but it’s appreciated if you do – you can also log in with OpenID.
* Independent from the official CouchSurfing organization, but supportive the CouchSurfing community.
* Very soon: a version in French and in other languages if requested by the community.
* We have registered several domains, and there will be a discussion about the domain name where all participants are welcome to join.
* Several nice extensions are installed, and if needed I’ll be happy to install more.
* The costs of running a wiki are very low – to me. No worries about that, I’m happy to take care of the technical and financial aspects of the server.
* In the future we’ll have XML dumps for downloading.

Let me know if there are any issues. And… Enjoy!

some thoughts about positive action

I’ve been a couchsurfing volunteer for about 9 months, in which I started the couchsurfing wiki, did tons of work on the code, and much more. I was trying to open the organization in a radical way, pushing for a free software license of the code and creating a bit of chaos here and there.

The day I quit 3 other coders who had contributed considerable work to the CS code base quit as well. It was a sad day. However, we thought that opencouchsurfing.org would be able to put pressure on the organization to open up. We thought wrong, obviously.

Now and then I’ve seen people quit volunteering for CS, for reasons uncommon to most organization. Still, I thought couchsurfing would continue, and people would be reasonably happy to volunteer within the framework provided.

Currently, with so many long-term volunteers quitting in such a short time span I’m wondering: what can we do to really open up couchsurfing – even if just a tiny wee bit? (And I prefer to wonder openly.) And is it possible to do this all together? Apparently the people who were against opencouchsurfing in the past seem to be sharing several goals. Is there another way to peacefully make a positive difference?

All the long-term volunteers are or have been friends with members of the leadership team, can we do something with that?

Or can a consensus be found to start something new or revive BeWelcome?

(Feel free to contact me by email if you prefer, firstname dot lastname at gmail dot com – I’ll keep things private if you prefer so.)

Alleged rape through CouchSurfing

I just read this article on the British Dailiy Mail web site.

Terrible, terrible news. I only hope this leads to CouchSurfing improving the trust systems. I hope they don’t use it to promote verification even more, or make verification compulsory.

Hospitality Club Dictatorship

Seriously, since the beginning this is one of my most important dogmas for the HC: no official structure for decision taking. I will always discuss issues openly with the people involved and with knowledge to come to good decisions that are the best for the network. But the final decision will always be with me.

This excerpt is from an e-mail by Veit Kühne (dated, 19 Jan 2005) as an answer to a Hospitality Club volunteer discussion. It has now been published on Wikileaks. According to Wikileaks’ “Latest Leaks and Censored Media”, Hospitality Club founder Veit Kühne planned organizational dictatorship for life and the e-mail “describes his plans for the power structure of the club: a benevolent dictatorship for life”.

Three and a half years after writing this e-mail, Veit also publicly gave away his strategy for taking over BeWelcome, the democratic hospitality exchange network that was started as a result of Veit’s ignorance towards members and volunteers of Hospitality Club.

Read the full e-mail “HC democracy and strategy” at Wikileaks.

“Mark in the verification icons going away”

A good day for CouchSurfing! Leadership is still listening to members. Gadget made the announcement Ambassador’s Public:

Yes, true! We have listened to your comments on the ? Mark that was in the new verification iconography. We agree that it is not the best way to represent a persons image or character, so we are removing it Monday. We ‘reload’ the site with all the weeks updates every Monday, so you will notice the change then.

Checklist to Evaluate a Nonprofit Board of Directors

Last night I was skimming through a book about fundraising. I was surprised to see that members of the Board of Directors are tacitly supposed to give to the charity. So I googled a bit and found this Checklist to Evaluate a Nonprofit Board of Directors (courtesy of Greater Twin Cities United Way).

It’s hard to assess in how far the CouchSurfing Board is meeting these requirements, apart from 4 (recommended) and 15 (essential): all 5 members of the board have American citizenship, are living in California, are in their thirties, there is one female member and 3 out of 5 are receiving a salary.

Most of the other points don’t seem to be available for public scrutiny (at this point it’s even unclear to me if there are any bylaws).  It would be nice if there were a bit more clarity about this charity.

Rating
*
Indicator Met Needs
Work
N/A
E 1. The roles of the Board and the Executive Director are defined and respected, with the Executive Director delegated as the manager of the organization’s operations and the board focused on policy and planning
R 2. The Executive Director is recruited, selected, and employed by the Board of Directors. The board provide clearly written expectations and qualifications for the position, as well as reasonable compensation.
R 3. The Board of Directors acts a governing trustees of the organization on behalf of the community at large and contributors while carrying out the organization’s mission and goals. To fully meet this goal, the Board of Directors must actively participate in the planning process as outlined in planning sections of this checklist.
R 4. The board’s nominating process ensures that the board remains appropriately diverse with respect to gender, ethnicity, culture, economic status, disabilities, and skills and/or expertise. NO
E 5. The board members receive regular training and information about their responsibilities.
E 6. New board members are oriented to the organization, including the organization’s mission, bylaws, policies, and programs, as well as their roles and responsibilities as board members.
A 7. Board organization is documented with a description of the board and board committee responsibilities.
A 8. Each board has a board operations manual.
E 9. If the organization has any related party transactions between board members or their family, they are disclosed to the board of directors, the Internal Revenue Service and the auditor.
E 10. The organization has at least the minimum number of members on the Board of Directors as required by their bylaws or state statute.
R 11. If the organization has adopted bylaws, they conform to state statute and have been reviewed by legal counsel.
R 12. The bylaws should include: a) how and when notices for board meetings are made; b) how members are elected/appointed by the board; c) what the terms of office are for officers/members; d) how board members are rotated; e) how ineffective board members are removed from the board; f) a stated number of board members to make up a quorum which is required for all policy decisions.
R 13. The board of directors reviews the bylaws.
A 14. The board has a process for handling urgent matters between meetings.
E 15. Board members serve without payment unless the agency has a policy identifying reimbursable out-of-pocket expenses. NO
R 16. The organization maintains a conflict-of-interest policy and all board members and executive staff review and/or sign to acknowledge and comply with the policy.
R 17. The board has an annual calendar of meetings. The board also has an attendance policy such that a quorum of the organization’s board meets at least quarterly.
A 18. Meetings have written agendas and materials relating to significant decisions are given to the board in advance of the meeting.
A 19. The board has a written policy prohibiting employees and members of employees’ immediate families from serving as board chair or treasurer.
Indicators ratings: E=essential; R=recommended; A=additional to strengthen organizational activities

Scalability…

The latest high season welcome message on CouchSurfing… I get it about 70% of the time I try to log on… hm… scalability problems? Let`s hope it is easy to solve!