Bug 392572

Summary: Data security Risk / all mails visible
Product: [Websites] bugs.kde.org Reporter: sac <milakam>
Component: generalAssignee: KDE sysadmins <sysadmin>
Status: RESOLVED NOT A BUG    
Severity: normal CC: bcooksley, nalvarez, sheedy
Priority: NOR    
Version First Reported In: unspecified   
Target Milestone: ---   
Platform: Other   
OS: Linux   
Latest Commit: Version Fixed/Implemented In:
Sentry Crash Report:

Description sac 2018-03-31 17:28:18 UTC
Hi,

I don't want that my mail is visible to everyone. Not sure if someone can create a script, parse some bug reports and pass all the assigned mail adresses in clear text.

However I did receive spam with mail adresses that were not known elsewhere.

At least there should be an option to disable public visibility of the own mail adress. 

This is a data security nightmare.
Comment 1 Nicolás Alvarez 2018-03-31 18:29:55 UTC
You're loudly warned about this when signing up: https://bugs.kde.org/createaccount.cgi
Comment 2 Ben Cooksley 2018-03-31 21:17:17 UTC
This is a limitation of how Bugzilla is designed (intentional or not, email addresses being public are part of how it works), and you are warned during the registration process that this is what will be happening (which is why it recommends you use something other than your primary account)