Not signed in (Sign In)

Categories

Vanilla 1.1.5 is a product of Lussumo. More Information: Documentation, Community Support.

Help keep Vanilla free:
Welcome Guest!
Want to take part in these discussions? If you have an account, sign in now.
If you don't have an account, apply for one now.
    • CommentAuthorfinnish
    • CommentTimeSep 1st 2006
     # 1
    Yeah, just checked out again.

    1. I'm a registered and logged in member.
    2. I checkout someone's personal account page and see email - n/a
    I can't see someone's email even if i'm registered and logged in - spam countermeasure, right?

    1. I'm not logged in (registration doesn't matter).
    2. I goto Sign In screen, Click Forgot Password and enter someone's username and then i see his email revealed in a message saying that instructions have been mailed to his inbox.
    Even unlogged user can see someone's email address

    My suggestion


    Just remove the email address from that message. Or maybe add a captcha to forgot my password screen.
    •  
      CommentAuthorWallPhone
    • CommentTimeSep 1st 2006
     # 2
    Here is some prior discussion on this topic, as well as two ways to prevent the email from being revealed.

    http://lussumo.com/community/discussion/3362/
    •  
      CommentAuthorMark
    • CommentTimeSep 1st 2006
     # 3
    Wierd. I never thought of that.

    The reason I put the email in there in the first place is because I've used password retrievals before where I can't remember which email address I had used on the site. If it is an email that I no longer have access to, I want to be aware of it so I can contact the admins about it.

    Do you think just displaying the domain is a good enough resolution?

    Like, "A message has been sent to your hotmail.com email address with password reset instructions"
    • CommentAuthorfinnish
    • CommentTimeSep 1st 2006
     # 4
    maybe just use some javascript document.write to output it? then spambots won't be able to read it..
    there's a lot scripts and plugins for blogs (i use Textpattern) that do this like this somefunction("my@email.addr") or somefunction(variable_with_mail_address) to zazzle the output through javascript..

    or display a domain name. but this won't help me, i have 4 accounts on gmail.com, you see..
    • CommentAuthorfinnish
    • CommentTimeSep 1st 2006
     # 5
    and a captcha may help, when a user is forced to solve captcha when entering username
    • CommentAuthorMadster
    • CommentTimeSep 1st 2006
     # 6
    my guess is if you can read it in plaintext, so can bots.
    The domain is good enough i guess.
  1.  # 7
    JS would work to avoid spambots but the issue here is for users privacy, finnish. I thought the same as you the first time round till someone pointed out the reason users hid their email is cause they didnt want people knowing it.

    I'm guessing either the domain or the username would work. But i use the same username for a couple of my domains.
    Perhaps you could do some funky 1st/3rd/5th character thing? i.e. b*d*s**@h*t*a**.com thing? :D
    •  
      CommentAuthorJazzman
    • CommentTimeSep 2nd 2006
     # 8
    eeek!! Someone tried to hack my account :P I got a Lussumo password-reset email and it sure wasn't me who activated that :D
    •  
      CommentAuthorDinoboff
    • CommentTimeSep 2nd 2006
     # 9
    • CommentAuthorfinnish
    • CommentTimeSep 2nd 2006
     # 10
    Jazzman, i did it :)
    just was browsing around some of your Vanilla Extensions and tried your username.
    sorry
Add your comments
    Username Password
  • Format comments as