Important: when posting, please provide your Club Number at a minimum, and as many details as possible.
For further info, please read This page before posting.

Do not show pop-up with users on the login screen

  • tm123
  • tm123's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 5
  • Thanks: 0

Do not show pop-up with users on the login screen

1 year 1 month ago
#93987
When loggin in there is this functionality that shows member names after typing first 4 characters:Enter your E-mail, Name, or Username, then select your Name or Username from the pop-up list that displays.
I don't think it's a good idea - it's leaking the names of all the members, even if they choose not to make their name public.
I didn't find anything in the settings to disable this behaviour.
I would suggest to remove it completely.
The topic has been locked.
  • NotLiable
  • NotLiable's Avatar
  • Offline
  • FreeToastHost Ambassador
  • FreeToastHost Ambassador
  • Posts: 275
  • Thanks: 41

Re: Do not show pop-up with users on the login screen

1 year 1 month ago
#93992
The pop-up list that displays is an auto-complete feature in the underlying code.  While yes, it does show names of members who have chosen not to make their profile public (which only shows name and member/officer status as a minimum), I don't see where this is terribly problematic.  Are those members, for whatever reason, totally reluctant to even admit that they are club members?
Yes, you are correct, that there is presently no disable setting, but again, I fail to see how this make-it-faster-and-easier-for-me-to-log-in feature is so troubling.
 
Arthur Farnsworth, DTM, PM4
We The Speakers, 9376
In-Person Toastmasters, 3474192
The topic has been locked.
  • tm123
  • tm123's Avatar Topic Author
  • Offline
  • New Member
  • New Member
  • Posts: 5
  • Thanks: 0

Re: Do not show pop-up with users on the login screen

1 year 1 month ago
#93996
To make it simple - it is not about user's preference - it is a security risk. It allows potential attacker to gather valid user names and then use another attack (ie password staffing) to break into that account.
Do not just believe me - have a look at "Account Enumeration" vulnerability, for example:
owasp.org/www-project-web-security-testi...essable_User_Account
www.virtuesecurity.com/kb/username-enumeration/

Please consider removing it from the code completely.
The topic has been locked.
  • Brian
  • Brian's Avatar
  • Offline
  • Administrator
  • Administrator
  • Posts: 11193
  • Thanks: 3691

Re: Do not show pop-up with users on the login screen

1 year 1 month ago - 1 year 1 month ago
#93998
Your issue has already been addressed. Those who do not want their name exposed can use the Username option.

 
Thank you,

Brian McDonald DTM
Silver and Wiser Online Toastmasters Club #777940

Technical Support Consultant for FreeToastHost
Last edit: 1 year 1 month ago by Heni.
The following user(s) said Thank You: Heni
The topic has been locked.
Moderators: BrianHeniPamrhtaylor3marc33NotLiableNSBjgavinLcala305peterb323DebbieT
Time to create page: 0.145 seconds