haxball / haxball-issues

113 stars 42 forks source link

Invasion of Privacy Laws? #2143

Open dvzq opened 2 months ago

dvzq commented 2 months ago

Dear All,

I'm writing to inquire about the data collection practices on haxmods.com. While visiting the website, I came across a feature that seemed to collect user IP addresses. This raised a concern for me, as it appeared to go beyond what some users, myself included, might expect.

Recently, I was banned from a Haxmods room. In addition to player.auth and player.conn, it seems my IP address may have also been used to extend the ban to the site and all its rooms. There's also a feature that appears to detect the use of VPNs.

My question is: Does Haxmods have the right to collect users' IP like that?

Furthermore, I'd like to understand the legality of collecting and using user IP addresses in this way, particularly when a ban is extended beyond a specific room. Since my IP may have been shared with a third party (haxmods.com), I'm concerned about potential privacy implications.

Thank you for your time and consideration.

SCR-20240430-jsxb SCR-20240430-nyob
Haxmods commented 2 months ago

Hi, Your ban from our haxball rooms and ban from the website are from 2 completely different incidents. Let me explain each incident.

Website: You created 70 new user accounts (each with a random nonsense name from mashing your keyboard) in the space of 25 minutes. Clear abuse and was detected as suspicious by the webhost firewall.

Haxball Rooms: You joined 5 different rooms at the same time, set AFK status and spammed the chat rooms non stop for 3 hours. Either you have a lot of patience or you used a bot to spam chat. Received multiple complaints from others before action was taken.

It seems you only had malicious intent in both incidents.

dvzq commented 2 months ago

Dear Haxmods Team,

I am writing to express my concern about being banned from your Discord server. I am disappointed to be held responsible for a situation that appears to be a result of unclear policies and potential shortcomings in your moderation system.

Firstly, after reviewing your terms of service at https://haxmods.com/terms and privacy policy at https://haxmods.com/privacy, I could not locate any mention of limitations on the number of accounts a single user can create. Given this lack of clarity, I wouldn't appreciate an explanation for why my account was banned.

Secondly, it seems your rooms are equipped with spam detection tools. If I was able to send spam messages, wouldn't this indicate a potential issue with the spam filtering system rather than my actions?

Finally, on both occasions I entered the Haxmods Discord server, I was banned without being informed of the specific reason. Transparency is crucial, and I would like to understand what actions I took that violated your server's rules.

Banning me does not address the underlying concerns. I urge you to reconsider this action and provide a clear explanation for the ban. Additionally, I believe a review of your account creation policy and the effectiveness of your spam filters would be beneficial.

Thank you for your time and attention to this matter.

Sincerely,

dvzq commented 2 months ago

I'm still skeptical about the authenticity of the first reason you gave:

  1. I created 70 new user accounts in about 25 minutes, around 18:00–19:00 GMT +8, on 04/29/2024. However, it wasn't until the next morning, after you banned me from the haxmods room in haxball, that I couldn't access the site. How do you explain this? Didn't you illegally collect users' IPs when they linked their Haxmods accounts to accounts on your website by chatting "!login CODE" in the Haxmods room on Haxball (code taken from haxmods.com)?

  2. If the webhost firewall really works, why wasn't I banned from the web when I created a series of accounts from ID 7920–8000 a few months ago (I wasn't banned from the room at that time)?

Again, I doubt they aren't two different incidents.

Haxmods commented 2 months ago

You were banned initially on the website and I unbanned you promptly giving you the benefit of the doubt. You then proceeded to spam the haxball rooms with messages about selling haxmods accounts the next day. You were logged into your "Beavis" account while you were spamming the hax rooms which led me to discover that the "Beavis" account was linked to the attack from the night before so I reinstated the website ban. There is nothing illegal about logging ip address for various reasons including detection and prevention of malicious activities and fraud. When you are banned in a haxball room, your ip is banned from re-entering the room. Has always been this way since the beginning of haxball.

Your discord ban was also for spamming multiple channels with the same message and your 2nd discord ban was for circumventing the first ban. (Clearly you didn't mean a single word you said in your good bye message)

This is not the platform to discuss your ban so it will be my last response here. You can appeal your ban by emailing contact@haxmods.com