| View previous topic :: View next topic |
| E-Mail visibility in Bugzilla |
| no change |
|
2% |
[ 1 ] |
| ALL addresses hidden always |
|
8% |
[ 4 ] |
| ALL addresses hidden to non-signed in |
|
64% |
[ 31 ] |
| ALL addresses hidden to non-editbugs users (developer) |
|
2% |
[ 1 ] |
| ALL addresses hidden always, but @gentoo.org addresses always visible |
|
2% |
[ 1 ] |
| ALL addresses hidden to non-signed in, but @gentoo.org addresses always visible |
|
12% |
[ 6 ] |
| ALL addresses hidden to non-editbugs users (developer), but @gentoo.org addresses always visible |
|
8% |
[ 4 ] |
|
| Total Votes : 48 |
|
| Author |
Message |
idl0r Developer


Joined: 24 Jan 2008 Posts: 11
|
Posted: Fri Jan 08, 2010 7:23 pm Post subject: Decide about E-Mail visibility in Bugzilla (spam) |
|
|
Dear Community,
you've surely noticed more spam, in case you have a bugzilla account.
Now you have the chance to vote for your favourite solution, see also
spammers can read the email addresses of the users. |
|
| Back to top |
|
 |
Jim6 Tux's lil' helper

Joined: 08 Apr 2005 Posts: 101
|
Posted: Fri Jan 08, 2010 7:44 pm Post subject: |
|
|
Voted: ALL addresses hidden to non-signed in
It's important that there's a strong CAPTCHA for registering as well though.
Perhaps set a time limit on accepting votes?
Last edited by Jim6 on Fri Jan 08, 2010 7:45 pm; edited 1 time in total |
|
| Back to top |
|
 |
idl0r Developer


Joined: 24 Jan 2008 Posts: 11
|
Posted: Fri Jan 08, 2010 7:45 pm Post subject: |
|
|
| Jim6 wrote: | | Perhaps set a time limit on accepting votes? |
Its set to 15 days. |
|
| Back to top |
|
 |
robbat2 Developer

Joined: 19 Feb 2003 Posts: 67
|
Posted: Fri Jan 08, 2010 7:56 pm Post subject: |
|
|
| Jim6 wrote: | It's important that there's a strong CAPTCHA for registering as well though.
|
What's your definition of strong CAPTCHA?
The last public state-of-the-art in defeating reCAPTCHA is 5% success rate:
http://bitland.net/captcha.pdf
The last time we proposed CAPTCHA (for mailing list subscription confirmations), we actively got complaints from our visually impaired users.
http://thread.gmane.org/gmane.linux.gentoo.project/714 |
|
| Back to top |
|
 |
V-Li Developer

Joined: 03 Jan 2006 Posts: 597
|
Posted: Fri Jan 08, 2010 8:10 pm Post subject: |
|
|
Developer addresses should always be visible in my eyes. So I voted for obfuscation for non-logged in with exception of @gentoo.org addresses. _________________ Christian Faulhammer, Gentoo Lisp project, GNU Emacs wrangler
http://www.gentoo.org/proj/en/lisp/ #gentoo-lisp on FreeNode
http://gentoo.faulhammer.org/ |
|
| Back to top |
|
 |
timeBandit Administrator


Joined: 31 Dec 2004 Posts: 2667 Location: here, there or in transit
|
Posted: Fri Jan 08, 2010 8:16 pm Post subject: |
|
|
Could addresses be HTML-entity encoded when displayed, as well? That would thwart most bots, I would think. _________________ Plants are pithy, brooks tend to babble--I'm content to lie between them.
Super-short f.g.o checklist: Search first, strip comments, mark solved, help others. |
|
| Back to top |
|
 |
robbat2 Developer

Joined: 19 Feb 2003 Posts: 67
|
Posted: Fri Jan 08, 2010 8:22 pm Post subject: |
|
|
| timeBandit wrote: | | Could addresses be HTML-entity encoded when displayed, as well? That would thwart most bots, I would think. |
Nope, analysis of spambots have shown that they can pick up most forms of email obfuscation. Really, it's just regex. |
|
| Back to top |
|
 |
jmbsvicetto Moderator


Joined: 27 Apr 2005 Posts: 4725 Location: Angra do Heroísmo (PT)
|
Posted: Fri Jan 08, 2010 8:33 pm Post subject: |
|
|
| V-Li wrote: | | Developer addresses should always be visible in my eyes. So I voted for obfuscation for non-logged in with exception of @gentoo.org addresses. |
I agree with Fauli. _________________ Jorge.
Your twisted, but hopefully friendly daemon.
AMD64 / x86 / Sparc Gentoo
Help answer || emwrap.sh
|
|
| Back to top |
|
 |
Etal Veteran


Joined: 15 Jul 2005 Posts: 1580
|
Posted: Fri Jan 08, 2010 9:03 pm Post subject: |
|
|
I voted for "ALL addresses hidden to non-signed in" because that seems to work.
When I first signed up for the gentoo bugzilla years ago, I soon noticed a large influx of spam in my spam folder (having 'a' as the first letter didn't help)
About a year ago, I needed to sign up for some KDE mailinglists, so I opened a new account and also set my KDE bugzilla account to point there. In that year, I haven't received a single spam message. I have significantly more activity in the KDE bugzilla than on Gentoo's.
The way they do it is that for all the non-logged-in users, only the name is shown. When the user is logged in, the name becomes a "mailto:" link.
As for the @gentoo.org addresses, although I'm not a developer, I think it would be better to hide them as well because unless it is required by policy to use the gentoo email on bugzilla, it might discourage people from using them and that would make things confusing. And if you're already checking for them, you could just as well add "(dev123)" after the name or something to distinguish them and give hint at how to contact.
Well, just my 2¢ |
|
| Back to top |
|
 |
yngwin Developer


Joined: 19 Dec 2002 Posts: 4219 Location: Suzhou, China
|
Posted: Tue Jan 12, 2010 12:45 am Post subject: Re: Decide about E-Mail visibility in Bugzilla (spam) |
|
|
| idl0r wrote: | | you've surely noticed more spam, in case you have a bugzilla account. |
Hardly. A good spam filter takes care of that. _________________ "Those who deny freedom to others deserve it not for themselves." - Abraham Lincoln
Free Culture | Defective by Design | EFF |
|
| Back to top |
|
 |
Old School Apprentice


Joined: 20 Nov 2004 Posts: 230 Location: The Covered Bridge Capital of Oregon
|
Posted: Thu Jan 14, 2010 4:33 pm Post subject: |
|
|
ALL addresses hidden to non-signed in _________________ I am not young enough to know everything.
- Oscar Wilde |
|
| Back to top |
|
 |
aidanjt Veteran


Joined: 20 Feb 2005 Posts: 1096 Location: Rep. of Ireland
|
Posted: Thu Jan 14, 2010 8:14 pm Post subject: |
|
|
I have another suggestion to add to the poll, hide non-@gentoo.org addresses except from those on the CC list (which should be hidden to non-authenticated users). _________________
| drizek wrote: | | Here in America, we are like a bunch of shit-slinging monkeys. |
|
|
| Back to top |
|
 |
eccerr0r Advocate

Joined: 01 Jul 2004 Posts: 2354 Location: USA
|
Posted: Thu Jan 28, 2010 11:35 pm Post subject: |
|
|
I have a feeling if the spammer knows a bugzilla site has a lot of people going there, they will spend the effort for one person to sit there and solve the captcha puzzle and then automate the rest. So unless there's a captcha puzzle for *every* email query and/or post this won't work.
At least that's how I think my phpbb2 got captcha cracked despite not really getting much traffic. I knew my "custom" captcha would fail most bots but recently it too got hacked. Since every post is somewhat like an email, I'm sure it would turn off people from posting if I made every post require a captcha puzzle solve.
sigh... $*#@ these people who respond to spam, making spam lucrative!  _________________ Core2Quad 9550S/4GB/4x500G RAID5/RadeonHD 5770
What the heck am I advocating? |
|
| Back to top |
|
 |
Rhywek n00b

Joined: 02 Jan 2005 Posts: 39
|
Posted: Sun Aug 29, 2010 6:13 pm Post subject: |
|
|
Looks like 98% of people want the change to happen, and hide the emails. So anybody knows if some solution will be implemented?
As a non-gentoo-dev, I would like my email to be invisible in bugzilla. There should be at least some option to hide it in account preferences, but there is none... :-( |
|
| Back to top |
|
 |
idl0r Developer


Joined: 24 Jan 2008 Posts: 11
|
Posted: Sun Aug 29, 2010 6:39 pm Post subject: |
|
|
| Rhywek wrote: | Looks like 98% of people want the change to happen, and hide the emails. So anybody knows if some solution will be implemented?
As a non-gentoo-dev, I would like my email to be invisible in bugzilla. There should be at least some option to hide it in account preferences, but there is none... :-( |
Addresses will be hidden for not logged in users in bugzilla-3. There is currently no ETA, sorry. |
|
| Back to top |
|
 |
|