https://bugzilla.wikimedia.org/show_bug.cgi?id=29852

       Web browser: ---
             Bug #: 29852
           Summary: email address on bugzilla account registration could
                    be disclosed accidentally
           Product: Wikimedia
           Version: unspecified
          Platform: All
        OS/Version: All
            Status: NEW
          Severity: normal
          Priority: Unprioritized
         Component: Bugzilla
        AssignedTo: [email protected]
        ReportedBy: [email protected]
                CC: [email protected], [email protected]
    Classification: Unclassified


The bugzilla system does not really respect [[WP:ANON]] - the account creation
here https://bugzilla.wikimedia.org/createaccount.cgi  which is needed to
report bugs on wikimedia's servers needs a valid(!) mail address. Users often
have real name mail addresses while being pseudonymous on-wiki. Users who do
not exactly read the message on the registration page can be easily tricked to
disclose their real name since the email address will be public in bugzilla!

This is especially bad for people who do not speak English - or do only speak a
bit. They could simply not understand what will happen with their email
address. It is VERY uncommon that a email address which is required(!) for
registration is made public. 

Bugzilla links are spread in our projects in village pump discussions and so
on. 

---

Simple: solution do not make email adresses public and do not require email
adresses for registration.

-- 
Configure bugmail: https://bugzilla.wikimedia.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are on the CC list for the bug.

_______________________________________________
Wikibugs-l mailing list
[email protected]
https://lists.wikimedia.org/mailman/listinfo/wikibugs-l

Reply via email to