View Issue Details
ID | Project | Category | View Status | Date Submitted | Last Update |
---|---|---|---|---|---|
07382 | Feature requests | Import/Export | public | 2010-01-06 14:47 | 2013-05-28 20:59 |
Reporter | Assigned To | ||||
Priority | normal | Severity | feature | ||
Status | acknowledged | Resolution | open | ||
Summary | 07382: Mailserver-Admin can guess the ID of the invited survey-user | ||||
Description | Since the ID for the users gets calculated by the import (so, if the import is in alphabetical order we have an incremented order also in the IDs), someone could try to guess the ID of users if he has access to the mailserver-logfiles. Since the Webserver-Admin is most of the time also the admin of the mailserver on localhost, he would now have the possibility to de-anonymize some surveys. | ||||
Additional Information | A possible solution: Randomize the sending of the mails Thank you in advance ;) | ||||
Tags | No tags attached. | ||||
Bug heat | 4 | ||||
Story point estimate | |||||
Users affected % | |||||
Server admin can allways know what is done on is server. tail -f /var/log/mail.log for mail .... |
|
Mail is not a secure format. |
|
Date Modified | Username | Field | Change |
---|---|---|---|
2013-05-24 19:16 | DenisChenu | Note Added: 25362 | |
2013-05-28 20:59 | mlhess | Note Added: 25403 |