Last modified: 2014-09-09 00:36:06 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T2148, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 148 - Bugzilla email address privacy concerns
Bugzilla email address privacy concerns
Product: Wikimedia
Classification: Unclassified
Bugzilla (Other open bugs)
All All
: Lowest enhancement with 5 votes (vote)
: ---
Assigned To: Nobody - You can work on this!
: upstream
: 9872 11048 11898 29852 (view as bug list)
Depends on: 9872 16777
Blocks: 4005
  Show dependency treegraph
Reported: 2004-08-16 16:58 UTC by Steve Sliva
Modified: 2014-09-09 00:36 UTC (History)
14 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Description Steve Sliva 2004-08-16 16:58:50 UTC
Users are not advised upon creating an account at MediaZilla that their email
address will become their username and be visible to anyone on all MediaZilla
bug reports voted on or created by that user.

At the least, the create a new account page should advise users of the lack of
email address privacy.  (Personally, I assumed that email would be required to
confirm that I was a real live person, and then allow me to create an account,
not for becoming my username.)
Comment 1 Antoine "hashar" Musso (WMF) 2004-08-16 17:21:17 UTC
You might want to report it to the bugzilla developpers as well :
Comment 2 Antoine "hashar" Musso (WMF) 2005-01-20 08:16:14 UTC
To be reported to bugzilla team.
Comment 3 Phillip Stewart 2005-08-10 17:28:02 UTC
A little is already done. @ is used instead of @.

Bugzilla spam prevention (tracking anti-spam-spiders/harvesters bugs)
Comment 4 Aryeh Gregor (not reading bugmail, please e-mail directly) 2007-08-23 20:29:08 UTC
*** Bug 11048 has been marked as a duplicate of this bug. ***
Comment 5 Brion Vibber 2008-12-28 21:51:45 UTC
There's a number of third-party patches/tweaks to BZ to suppress display of email addresses unless one's logged in and such. Clearer display of privacy info would also be good!
Comment 6 Brion Vibber 2009-04-09 00:24:04 UTC is marked FIXED upstream:
"Email addresses should only be displayed to logged in users"

Should make it to a future release... (3.4?)
Comment 7 Brion Vibber 2009-08-12 23:44:50 UTC
Bulk-assigning open BZ issues to Fred.
Comment 8 Fred Vassard 2009-09-10 17:34:07 UTC
This will get corrected in the upcoming version of Bugzilla, which should make it here very soon.
Comment 9 MiG 2009-09-10 20:16:02 UTC
Please note that making email addresses invisible until you register just moves the problem up a tiny bit, spambots can easily register (as they do on various types of forum) and then still harvest email addresses.

What would help is either making email addresses invisible permanently (except for admins), or providing the user a choice between showing his email address (only for registered users, of course) or hiding it altogether.
Comment 10 lɛʁi לערי ריינהארט 2009-09-14 13:50:22 UTC
I think this can help:

Please see truncated email addresses at
subject: « make irc:// clickable links »

I think it's not done in but one can ask the maintainer:
maintainer      : 'platform-bugs\'

btw: shows install_version : '3.5' shows to maintainers:
A new Bugzilla version (3.4.2) is available at
Release date: 2009-09-11 shows version : '3.4.1',

Regards Reinhardt [[user:Gangleri]]
Comment 11 Chad H. 2010-01-19 20:44:36 UTC
*** Bug 9872 has been marked as a duplicate of this bug. ***
Comment 12 Chad H. 2010-01-19 20:58:31 UTC
Marking this fixed with the BZ 3.4 upgrade, bug 16777. E-mail addys aren't shown to unregistered users anymore.
Comment 13 Brion Vibber 2011-07-13 01:13:32 UTC
Reopening -- the upstream bug that was fixed doesn't solve the problem that email addresses are used as a primary identifier and are exposed to other users.
Comment 14 Brion Vibber 2011-07-13 01:13:48 UTC
*** Bug 29852 has been marked as a duplicate of this bug. ***
Comment 15 Brion Vibber 2011-07-13 01:14:36 UTC
*** Bug 11898 has been marked as a duplicate of this bug. ***
Comment 16 Antoine "hashar" Musso (WMF) 2012-03-04 13:04:58 UTC
Unassigning from fvassard at wikimedia dot org
Comment 17 Andre Klapper 2012-05-25 08:52:15 UTC
(In reply to comment #13)
> Reopening -- doesn't solve the problem that email addresses are used as 
> a primary identifier and are exposed to other users.

Upstream for that is
Comment 18 Andre Klapper 2014-01-31 22:14:23 UTC
Upstream ticket has an initial patch, so there is a small chance to see this in Bugzilla 5.0.
Comment 19 Quim Gil 2014-04-14 01:30:44 UTC
Related: a request for comments to move our bug reporting and more to Phabricator, where users' email addresses are kept private.

Details about the potential migration from Bugzilla to Phabricator are being discussed at 

Migrate Bugzilla to Phabricator

+ dependent tasks.
Comment 20 Quim Gil 2014-05-17 00:14:21 UTC
With the move to [[w:Phabricator]] approved, this request about visible email addresses in Bugzilla is Lowest priority. We are focusing in Wikimedia Phabricator Day 1.

Note You need to log in before you can comment on or make changes to this bug.