Topic-icon [SOLVED] Major Security Problem JFBConnect

Active Subscriptions:

None
Hi,

Please investigate this major privacy issue that only happens with JFBConnect. When I type my email address into Google I get 2 hits: one from SourceCoast.com and one from Joomla.org (which uses JFBConnect). The information shows your true name and other information connected to your email. This is a major privacy / security bug that needs to be addressed.

No other Joomla component does this.

Kindly fix this.

Rene
The topic has been locked.
Support Specialist
14 years 5 months ago #16644 by alzander
Rene,
The issue you mention has nothing to do with JFBConnect. There were 2 hits when I used your email address in Google: Our JFBConnect demo site and code.joomla.org:
1) On our demo site, we use Community Builder. We had the email field set to Profile, which showed this field to guest users. We agree, this was a bad setting, and have unpublished that from public view. That setting has nothing to do with JFBConnect.
2) Joomla Code is not even a Joomla site, and is in now way powered by JFBConnect. They are simply publishing your email address on that page as xxxx @nospam@ site.com. You'd need to contact them if you want that field removed.

Hope that helps explain, and thanks for pointing out the error on our demo site.. but, again, this is nothing to do with JFBConnect itself.

Alex
The topic has been locked.
Active Subscriptions:

None
14 years 5 months ago #16676 by fb_1582987308
Hi Alzander,

Thanks for fixing this issue.

Rene
The topic has been locked.
Support Specialist
14 years 5 months ago #16697 by alzander
No problem. Thanks for reporting it, and sorry for the possible scare you may have had. We always like to hear about possible security issues, and are glad to hear this wasn't an issue with JFBConnect.

Good luck,
Alex
The topic has been locked.