@Plykiya
It was coded in a weekend by a single person and then gradually improved on by a single person who isn't even a dev. We know it's shit lol, working on the v3 code is demoralizing to all of the devs. Hence why the plan is for a complete rewrite away from the existing code.
The admins have nothing to do with it, but you are right that the devs want to kill themselves looking at the current site code. Again, hence the plans for a rework. Everything we do is just firefighting attempts to keep v3 going until v5 exists.
That's a fine excuse and all, but why even waste the time to get all the way up to v3 in the first place if you're just rewriting it? Take the site down for a bit and finish the rewrite so users aren't still open and exposed and so your devs (sorry, I miswrote admins) can focus on one project instead of sloppily throwing together one that may never actually ship anytime soon (or at all, going by the track record) while patchworking the other one with toothpicks and glue? I seem to recall a very similar situation with v4, which was just never implemented because either it couldn't be coded well or because you were too lazy to implement it.
But at this point we've been on v3 for ages and there've hardly been ANY QoL features added, even simple ones, like a site theme that isn't just default Bootstrap. I dunno if that's just because your code is THAT bad or just from lack of desire to update them or just being too busy keeping the various fires from spreading, but it's still such a non-excuse to say "we're just rewriting the site, please keep using this site ad infinitum despite the glaring issues and just get ready for regular data breaches because until then we aren't doing anything."
Batoto had a support forums, an IRC channel, and reports. We have a support forum, a Discord, and reports. Your standards between us and Batoto are kind of... lol. Batoto even ran ads all the time too, you know? What we're doing with one tiny banner isn't even close to the level of ads they had.
I am a bit passive aggressive when people hold Batoto to some holy grail standard where everything was better when it was struggling to barely cope with Tachiyomi traffic and had to make the website accounts-only whereas we're pushing at least 20x the amount of traffic they were and getting told we're more incompetent than them because we're struggling to keep up with the upgrades required lol.
And ending sentences with lol is indeed something I can't really avoid.
I mentioned Batoto once at the beginning just referring to how MangaDex started (to sop up the pool of clout in the vacuum left by the site's closure). By no means do I hold them to some holy grail standard. I wasn't on board the ad train, and if I had needed a support I would have been very frustrated, as I was very frustrated when I needed assistance with an account issue here sometime last year. I didn't have a way to contact the admins except, as I said, to go into a huge public discord and hope that maybe an admin might answer my account question. By the way, that didn't happen and I had to use other means to fix my issue. I'm not drawing comparisons between MD and Batoto, it seems to be only you lacking the reading comprehension to see that, but after the way the site has been run since its inception, again I'm not surprised. But if you want a real direct comparison, Batoto was definitely a much better site because at least it worked, which is far more than I can say about MD most of the time.
Honestly though, if it helped the site's performance, I really wouldn't even mind if MD went accounts-only, because contrary to your boasting about how super good the load times are, several friends and I from before the breach and even one of the users posting here are still reporting higher than acceptable failure rates. And no, it's not because I just have bad Internet lol XD
Even in v5 it'll be a manual process. Sorry that you don't have to deal with the people attempting to upload ads and bait images to the website.
I don't care that it's a manual approval process, that's fine. I just think it's weird that to register a group you have to go into a forum thread and beg and wait for someone to add it. A simple form would be way more effective both for users and the admins. The fact that you responded in this way makes me think that v5 will continue this sloppy handling of group additions so if you're trying to advertise that, you're not doing a very good job at it. Even a rewrite isn't gonna fix the obvious infrastructure issues here.
2FA stops people from ever being able to access your account via a password. Assuming that the other 99% of people trying to get into your account are trying to do it by a db breach is just being insincere.
Sure but just about
any decent site engineer knows not to store session codes on the DB.
Well, feel free to make your own website. We don't ban people for criticizing us, lol. You're acting a bit silly.
Look, I get that I'm having a pretty big reaction to this, but it's really obvious through the OP and this response that you don't care about user data. I see people bragging about "well my data on here isn't important" or "I'm using a secure password" but given the size of your userbase, these people are more likely the exception than the rule, and as a site owner, do you not feel any sort of duty to protect the potentially vulnerable data of your users? I guess not, because if you did, the site wouldn't be running in this condition in the first place.
Anyways, hope any of this made it through, but judging by the tone of your response and the desperate attempt to find excuses, deflect by saying "other people did it too!" and not really address my issues, I'm not hopeful.