RESOLVED FIXED 197687
Tools using bugzilla email lists expose un-truncated and un-obfuscated email addresses
https://bugs.webkit.org/show_bug.cgi?id=197687
Summary Tools using bugzilla email lists expose un-truncated and un-obfuscated email ...
Tobi Reif
Reported 2019-05-08 01:23:21 PDT
My email address gets published un-truncated and un-obfuscated. Here's a list of the pages: (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) https://bit.ly/2DU2xGK Please make sure that my email address gets obfuscated or truncated on these pages (please send a request to the marc.info maintainers). Please also make sure that my email address gets obfuscated or truncated on the original pages (your pages) from which marc.info got the copies.
Attachments
Simon Fraser (smfr)
Comment 1 2019-05-08 09:55:32 PDT
Looks like marco.info is following webkit-unassigned (https://marc.info/?l=webkit-unassigned&r=1&w=2)
Tobi Reif
Comment 2 2019-05-09 03:21:33 PDT
One specific example: The bug page: https://bugs.webkit.org/show_bug.cgi?id=108929 Does not publish my email address. The message at the original location: https://lists.webkit.org/pipermail/webkit-unassigned/2013-March/1364285.html Has my email address, but at least the at-sign is replaced with " at ". Please make sure the email address gets truncated/obfuscated more strongly (on the whole site webkit.org) (ideally for all email addresses). The message copy at marc.info: https://marc.info/?l=webkit-unassigned&m=136360475701428 Contains my email address (you can find it right after "Comment #7 from Tobi Reif") in full, non-obfuscated and non-truncated. It even is featured verbatim in the source of the page - very easy to harvest even for simple spam bots. Since 2018-02-21 I have sent several emails to the maintainers of marc.info. They have not fixed the issue. Please make sure that the list admin of "Webkit-unassigned" will soon send a request to the marc.info maintainers https://marc.info/?q=about asking them to immediately obfuscate or/and truncate all instances of my email address on their site which have been fetched from "Webkit-unassigned" (currently all instances of my email address on marc.info are from "Webkit-unassigned"). (Feel free to expand the request to all email addresses fetched from your list/lists.)
Tobi Reif
Comment 3 2019-05-09 03:28:19 PDT
... and if marc.info gets the messages via an API please make sure that the email addresses are strongly truncated/obfuscated in the data supplied by the API.
Tobi Reif
Comment 4 2019-05-09 04:25:42 PDT
And thanks for looking into it!
Tobi Reif
Comment 5 2019-05-17 02:43:14 PDT
Please make sure that my email address gets truncated/obfuscated on all these marc.info pages: https://bit.ly/2DU2xGK (they all publish a "Webkit-unassigned" message). Please send a request to the contacts at https://marc.info/?q=about (there also is a contact at the bottom of the page after "send pizza").
Tobi Reif
Comment 6 2019-05-21 02:48:32 PDT
(Please make sure to not paste my email address here in this ticket. Thanks.)
Radar WebKit Bug Importer
Comment 7 2019-05-22 21:53:13 PDT
Tobi Reif
Comment 8 2019-05-28 23:59:52 PDT
I hope this issue can get resolved soon.
Tobi Reif
Comment 9 2019-06-24 01:05:30 PDT
I hope this issue can get resolved soon.
Tobi Reif
Comment 10 2019-07-19 02:39:17 PDT
I hope this issue can get resolved soon.
Tobi Reif
Comment 11 2019-08-20 01:50:15 PDT
I hope that this issue will be resolved soon. Thanks in advance!
Tobi Reif
Comment 12 2019-09-25 01:23:40 PDT
I hope this issue can get resolved soon.
Tobi Reif
Comment 13 2019-11-04 02:13:27 PST
I hope this issue can get resolved soon.
Tobi Reif
Comment 14 2020-03-12 02:04:22 PDT
Please make sure that my email address gets truncated/obfuscated on all these marc.info pages: https://bit.ly/2DU2xGK (they all publish a "Webkit-unassigned" message). Please send a request to the contacts at https://marc.info/?q=about (there also is a contact at the bottom of the page after "send pizza").
Tobi Reif
Comment 15 2020-04-24 02:13:49 PDT
It clearly doesn't help that I post here regularly. What could I do instead? The issue needs to get resolved. Has anything been tried? Is there any progress at all?
Tobi Reif
Comment 16 2020-05-05 01:06:20 PDT
You are passing on my email address, not actively but knowingly, for years, either via the some pages or via an API. And marc.info is publishing it. I had never consented to you passing on my email address. Please stop it. And please make sure that the past and future published copies of my bug reports on marc.info do not contain my email address (they got and are getting my email address through you).
Tobi Reif
Comment 17 2020-08-21 00:53:48 PDT
You are passing on my email address, not actively but knowingly, for years, either via the some pages or via an API. And marc.info is publishing it. I had never consented to you passing on my email address. Please stop it. And please make sure that the past and future published copies of my bug reports on marc.info do not contain my email address (they got and are getting my email address through you).
Tobi Reif
Comment 18 2020-12-14 01:48:54 PST
Is there anything I can do to help? You are passing on my email address, not actively but knowingly, for years, either via the some pages or via an API. And marc.info is publishing it. I had never consented to you passing on my email address. Please stop it. And please make sure that the past and future published copies of my bug reports on marc.info do not contain my email address (they got and are getting my email address through you).
Tobi Reif
Comment 19 2021-04-13 00:58:30 PDT
There currently still are several pages which publish my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.)
Tobi Reif
Comment 20 2022-01-04 06:28:49 PST
There currently are only three pages left which publish my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that these last three pages will disappear as well (and that my email address won't be shared through WebKit bug reports anymore).
Tobi Reif
Comment 21 2022-04-26 07:44:54 PDT
I hope that you can ensure that these last three pages will disappear as well.
Tobi Reif
Comment 22 2022-05-11 07:02:45 PDT
As far as https://bit.ly/2DU2xGK shows, the problem has been resolved. My sincere thanks!
Tobi Reif
Comment 23 2022-06-11 10:02:12 PDT
Unfortunately, the status went from zero back to several: There currently are two pages listed which publish my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that these two pages will disappear as well (and that my email address won't be shared through WebKit bug reports anymore).
Tobi Reif
Comment 24 2022-08-01 02:50:07 PDT
There currently is one page listed which publishes my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that this page will disappear as well (and that my email address won't be shared through WebKit bug reports anymore).
Tobi Reif
Comment 25 2022-11-16 02:03:44 PST
There currently is one page listed which publishes my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that this page will disappear as well (and that my email address won't be shared through WebKit bug reports anymore).
Tobi Reif
Comment 26 2023-04-16 07:20:39 PDT
There currently are four pages listed which publish my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that these pages will disappear (and that my email address won't be shared through WebKit bug reports anymore).
Tobi Reif
Comment 27 2023-05-12 02:26:45 PDT
There currently are four pages listed which publish my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that these pages will disappear (and that my email address won't be shared through WebKit bug reports anymore).
Tobi Reif
Comment 28 2023-12-11 02:31:25 PST
There currently is one page listed which publishes my email address which they got from WebKit bug reports: https://bit.ly/2DU2xGK (A URL-shortener is used so that I don't have to paste the verbatim URL which includes my email address. The bit.ly URL resolves to a google.com search.) I hope that you can ensure that this page will disappear (and that my email address won't be shared through WebKit bug reports anymore).
Note You need to log in before you can comment on or make changes to this bug.