Launchpad leaks private email addresses

Bug #670220 reported by Delmir
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Launchpad itself
Invalid
Undecided
Unassigned

Bug Description

Hi, I have a dedicated account just to handle emails from Launchpad, and since yesterday I started to get junk email from different spammers. That means Launchpad is somehow leaking private email addresses. Unfortunately, I could not notice where or how the exploit is at. In any case, I changed my email address and blocked the old address in the mean time. Can someone please dig a little more and try to find how our email address are getting exposed? Thanks, Del

Tags: lp-registry
Revision history for this message
Gavin Panella (allenap) wrote :

You need to go to https://launchpad.net/~7-launchpad-net-delmir-com/+edit and select "Hide my email addresses from other Launchpad users".

Changed in launchpad:
status: New → Invalid
security vulnerability: yes → no
visibility: private → public
Revision history for this message
Delmir (delmir) wrote :

Gavin, the flag for "Hide my email addresses from other Launchpad users" was already set in "your personal details" page. Is there another place to set this flag? BTW, I find it interesting that if I use Google to search for my email address within quotes, then Google returns some Launchpad.net pages. It seems odd since I don't see my email address in those pages nor in the actual page "html" content. I'm still intrigued.

Revision history for this message
Robert Collins (lifeless) wrote : Re: [Bug 670220] Re: Launchpad leaks private email addresses

Which pages?

Revision history for this message
Curtis Hovey (sinzui) wrote :

I believe delmir needs to change his Launchpad ID. His email address is very similar to his launchpad ID. delmir, use the Change details link on your profiles page to give yourself a sane name and display name.

affects: launchpad → launchpad-registry
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.