Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Decide about E-Mail visibility in Bugzilla (spam)
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Gentoo Chat
View previous topic :: View next topic  

E-Mail visibility in Bugzilla
no change
2%
 2%  [ 1 ]
ALL addresses hidden always
8%
 8%  [ 4 ]
ALL addresses hidden to non-signed in
64%
 64%  [ 31 ]
ALL addresses hidden to non-editbugs users (developer)
2%
 2%  [ 1 ]
ALL addresses hidden always, but @gentoo.org addresses always visible
2%
 2%  [ 1 ]
ALL addresses hidden to non-signed in, but @gentoo.org addresses always visible
12%
 12%  [ 6 ]
ALL addresses hidden to non-editbugs users (developer), but @gentoo.org addresses always visible
8%
 8%  [ 4 ]
Total Votes : 48

Author Message
idl0r
Developer
Developer


Joined: 24 Jan 2008
Posts: 11

PostPosted: Fri Jan 08, 2010 7:23 pm    Post subject: Decide about E-Mail visibility in Bugzilla (spam) Reply with quote

Dear Community,

you've surely noticed more spam, in case you have a bugzilla account.
Now you have the chance to vote for your favourite solution, see also
spammers can read the email addresses of the users.
Back to top
View user's profile Send private message
Jim6
Tux's lil' helper
Tux's lil' helper


Joined: 08 Apr 2005
Posts: 101

PostPosted: Fri Jan 08, 2010 7:44 pm    Post subject: Reply with quote

Voted: ALL addresses hidden to non-signed in

It's important that there's a strong CAPTCHA for registering as well though.


Perhaps set a time limit on accepting votes?


Last edited by Jim6 on Fri Jan 08, 2010 7:45 pm; edited 1 time in total
Back to top
View user's profile Send private message
idl0r
Developer
Developer


Joined: 24 Jan 2008
Posts: 11

PostPosted: Fri Jan 08, 2010 7:45 pm    Post subject: Reply with quote

Jim6 wrote:
Perhaps set a time limit on accepting votes?


Its set to 15 days.
Back to top
View user's profile Send private message
robbat2
Developer
Developer


Joined: 19 Feb 2003
Posts: 67

PostPosted: Fri Jan 08, 2010 7:56 pm    Post subject: Reply with quote

Jim6 wrote:
It's important that there's a strong CAPTCHA for registering as well though.


What's your definition of strong CAPTCHA?
The last public state-of-the-art in defeating reCAPTCHA is 5% success rate:
http://bitland.net/captcha.pdf

The last time we proposed CAPTCHA (for mailing list subscription confirmations), we actively got complaints from our visually impaired users.
http://thread.gmane.org/gmane.linux.gentoo.project/714
Back to top
View user's profile Send private message
V-Li
Developer
Developer


Joined: 03 Jan 2006
Posts: 597

PostPosted: Fri Jan 08, 2010 8:10 pm    Post subject: Reply with quote

Developer addresses should always be visible in my eyes. So I voted for obfuscation for non-logged in with exception of @gentoo.org addresses.
_________________
Christian Faulhammer, Gentoo Lisp project, GNU Emacs wrangler
http://www.gentoo.org/proj/en/lisp/ #gentoo-lisp on FreeNode

http://gentoo.faulhammer.org/
Back to top
View user's profile Send private message
timeBandit
Administrator
Administrator


Joined: 31 Dec 2004
Posts: 2667
Location: here, there or in transit

PostPosted: Fri Jan 08, 2010 8:16 pm    Post subject: Reply with quote

Could addresses be HTML-entity encoded when displayed, as well? That would thwart most bots, I would think.
_________________
Plants are pithy, brooks tend to babble--I'm content to lie between them.
Super-short f.g.o checklist: Search first, strip comments, mark solved, help others.
Back to top
View user's profile Send private message
robbat2
Developer
Developer


Joined: 19 Feb 2003
Posts: 67

PostPosted: Fri Jan 08, 2010 8:22 pm    Post subject: Reply with quote

timeBandit wrote:
Could addresses be HTML-entity encoded when displayed, as well? That would thwart most bots, I would think.

Nope, analysis of spambots have shown that they can pick up most forms of email obfuscation. Really, it's just regex.
Back to top
View user's profile Send private message
jmbsvicetto
Moderator
Moderator


Joined: 27 Apr 2005
Posts: 4725
Location: Angra do Heroísmo (PT)

PostPosted: Fri Jan 08, 2010 8:33 pm    Post subject: Reply with quote

V-Li wrote:
Developer addresses should always be visible in my eyes. So I voted for obfuscation for non-logged in with exception of @gentoo.org addresses.

I agree with Fauli.
_________________
Jorge.

Your twisted, but hopefully friendly daemon.
AMD64 / x86 / Sparc Gentoo
Help answer || emwrap.sh
Back to top
View user's profile Send private message
Etal
Veteran
Veteran


Joined: 15 Jul 2005
Posts: 1580

PostPosted: Fri Jan 08, 2010 9:03 pm    Post subject: Reply with quote

I voted for "ALL addresses hidden to non-signed in" because that seems to work.

When I first signed up for the gentoo bugzilla years ago, I soon noticed a large influx of spam in my spam folder (having 'a' as the first letter didn't help)

About a year ago, I needed to sign up for some KDE mailinglists, so I opened a new account and also set my KDE bugzilla account to point there. In that year, I haven't received a single spam message. I have significantly more activity in the KDE bugzilla than on Gentoo's.

The way they do it is that for all the non-logged-in users, only the name is shown. When the user is logged in, the name becomes a "mailto:" link.

As for the @gentoo.org addresses, although I'm not a developer, I think it would be better to hide them as well because unless it is required by policy to use the gentoo email on bugzilla, it might discourage people from using them and that would make things confusing. And if you're already checking for them, you could just as well add "(dev123)" after the name or something to distinguish them and give hint at how to contact.

Well, just my 2¢
Back to top
View user's profile Send private message
yngwin
Developer
Developer


Joined: 19 Dec 2002
Posts: 4219
Location: Suzhou, China

PostPosted: Tue Jan 12, 2010 12:45 am    Post subject: Re: Decide about E-Mail visibility in Bugzilla (spam) Reply with quote

idl0r wrote:
you've surely noticed more spam, in case you have a bugzilla account.

Hardly. A good spam filter takes care of that.
_________________
"Those who deny freedom to others deserve it not for themselves." - Abraham Lincoln
Free Culture | Defective by Design | EFF
Back to top
View user's profile Send private message
Old School
Apprentice
Apprentice


Joined: 20 Nov 2004
Posts: 230
Location: The Covered Bridge Capital of Oregon

PostPosted: Thu Jan 14, 2010 4:33 pm    Post subject: Reply with quote

ALL addresses hidden to non-signed in
_________________
I am not young enough to know everything.
- Oscar Wilde
Back to top
View user's profile Send private message
aidanjt
Veteran
Veteran


Joined: 20 Feb 2005
Posts: 1096
Location: Rep. of Ireland

PostPosted: Thu Jan 14, 2010 8:14 pm    Post subject: Reply with quote

I have another suggestion to add to the poll, hide non-@gentoo.org addresses except from those on the CC list (which should be hidden to non-authenticated users).
_________________
drizek wrote:
Here in America, we are like a bunch of shit-slinging monkeys.
Back to top
View user's profile Send private message
eccerr0r
Advocate
Advocate


Joined: 01 Jul 2004
Posts: 2354
Location: USA

PostPosted: Thu Jan 28, 2010 11:35 pm    Post subject: Reply with quote

I have a feeling if the spammer knows a bugzilla site has a lot of people going there, they will spend the effort for one person to sit there and solve the captcha puzzle and then automate the rest. So unless there's a captcha puzzle for *every* email query and/or post this won't work.

At least that's how I think my phpbb2 got captcha cracked despite not really getting much traffic. I knew my "custom" captcha would fail most bots but recently it too got hacked. Since every post is somewhat like an email, I'm sure it would turn off people from posting if I made every post require a captcha puzzle solve.

sigh... $*#@ these people who respond to spam, making spam lucrative! :-(
_________________
Core2Quad 9550S/4GB/4x500G RAID5/RadeonHD 5770
What the heck am I advocating?
Back to top
View user's profile Send private message
Rhywek
n00b
n00b


Joined: 02 Jan 2005
Posts: 39

PostPosted: Sun Aug 29, 2010 6:13 pm    Post subject: Reply with quote

Looks like 98% of people want the change to happen, and hide the emails. So anybody knows if some solution will be implemented?

As a non-gentoo-dev, I would like my email to be invisible in bugzilla. There should be at least some option to hide it in account preferences, but there is none... :-(
Back to top
View user's profile Send private message
idl0r
Developer
Developer


Joined: 24 Jan 2008
Posts: 11

PostPosted: Sun Aug 29, 2010 6:39 pm    Post subject: Reply with quote

Rhywek wrote:
Looks like 98% of people want the change to happen, and hide the emails. So anybody knows if some solution will be implemented?

As a non-gentoo-dev, I would like my email to be invisible in bugzilla. There should be at least some option to hide it in account preferences, but there is none... :-(


Addresses will be hidden for not logged in users in bugzilla-3. There is currently no ETA, sorry.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Gentoo Chat All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum