Pages: [1]   Go Down

Author Topic: Security  (Read 3357 times)

Peter Mellis

  • Full Member
  • ***
  • Offline Offline
  • Posts: 143
Security
« on: August 20, 2010, 10:45:20 am »

Yesterday I goggled my name and much to my surprise one of the things that came up was my profile on this forum. I thought that this information is password protected; if that is the case, then there is some kind of glitch here.
Logged

mguertin

  • Guest
Re: Security
« Reply #1 on: August 20, 2010, 03:02:03 pm »

Yesterday I goggled my name and much to my surprise one of the things that came up was my profile on this forum. I thought that this information is password protected; if that is the case, then there is some kind of glitch here.

Hi Peter

Your user information is public as this is a public forum.  Your email address is protected, but anything else you post here should be considered publicly accessible, that includes any information you include in your user profile aside from your email address.
Logged

PierreVandevenne

  • Sr. Member
  • ****
  • Offline Offline
  • Posts: 512
    • http://www.datarescue.com/life
Re: Security
« Reply #2 on: August 22, 2010, 07:26:24 pm »

As someone who has answered more than 100.000 support queries in the last 10 years, let me start by saying you are doing a great, patient and courteous job so far ;-)

This being said, as I said earlier, this profile information is definitely too easily available. There must be a setting that restricts access to the profile info to registered users (most boards I have worked with offer that option) and if there isn't, as a high profile user of this specific board software you could probably put that feature request through, possibly even defining it and helping with its implementation. Profile info is too easily available, in an easy automated way. It is very easy to collect a database about all the board's users and even, since you are a high traffic site and I doubt you have the resources to monitor your logs fully on a daily basis, to derive a lot of info from dynamic monitoring.

According to Michael's posts, the plan is to increase the value of this site for both the owners and the users. I am looking forward to it. But you will definitely have to find a way to keep the profile (or future extended profile) info private. From the site owner side, it is one important aspect of the value of your web site: you shouldn't allow third parties to collect your user info so easily. From the user side, you can be sure people aware of the permeability of the system will not share as much as you'd like and people unaware of those technical aspects may be unhappy to discover their info in a third party db or service, or even in Google. And this is even more so when users are encouraged to use real IDs.

Using real IDs linked to real profiles is, imho, the most basic level form of respect towards other boards and community members. Sharing it with the world is not the same thing.
Logged

mguertin

  • Guest
Re: Security
« Reply #3 on: August 24, 2010, 05:14:56 pm »

I've made some tweaks in this regard.  While it's not feasible to block the viewing of profile data or stats from members it was possible to block guests from viewing this information.  Not the solution you were looking for but I think it's a good compromise. 

Again I will iterate though that this is a public forum and consider anything you add to your profile (except your email address) as public information.
Logged

PierreVandevenne

  • Sr. Member
  • ****
  • Offline Offline
  • Posts: 512
    • http://www.datarescue.com/life
Re: Security
« Reply #4 on: August 26, 2010, 10:23:16 am »


> > There must be a setting that restricts access to the profile info to registered users

> While it's not feasible to block the viewing of profile data or stats from members it was possible to block guests from viewing this information.

Thanks - that's exactly what I meant. Re-reading my sentence I can see it is a bit ambiguous, but it was in the sense "restricted to authorized personnel only".
Logged
Pages: [1]   Go Up