Page MenuHomePhabricator

email-blocked users can register false email addresses
Closed, DeclinedPublic

Description

Users whose email has been blocked can still attempt to change their preferences and change their email addresses; this has been used to harass the blocking admin. (I've received several dozen "Wikipedia e-mail address confirmation" mails; it's just an annoyance, but still, email-blocked users shouldn't be able to futz with their email addresses anyway.)


Version: unspecified
Severity: minor

Details

Reference
bz15750

Event Timeline

bzimport raised the priority of this task from to Lowest.Nov 21 2014, 10:17 PM
bzimport set Reference to bz15750.
bzimport added a subscriber: Unknown Object (MLST).

ayg wrote:

An e-mail-blocked user can still receive e-mail notifications of various events, and can still receive e-mail, so they should be able to change their e-mail address. If someone already knows your e-mail address, can't they just harass you by sending you e-mails manually, just as easily as by changing their address to yours in the software?

We could still probably solve that problem by rate-limiting confirmation mails per-email-address.

Good point. My particular harasser specializes in totally petty minor league crap like this.