|
moderated
Re: Changing email address security issue
#misc
It may be that the problem lies in the wording on the Change Email page. Once you click on it, you're told "are you sure you want to change your email address - you must reconfirm your account" but
It may be that the problem lies in the wording on the Change Email page. Once you click on it, you're told "are you sure you want to change your email address - you must reconfirm your account" but
|
By
J_Catlady
·
#28328
·
|
|
moderated
Re: Changing email address security issue
#misc
I'm with the others, just the pure technical concept itself of being able to freely and easily change someone else's email address is inherently risky; so from that perspective, even if I see value in
I'm with the others, just the pure technical concept itself of being able to freely and easily change someone else's email address is inherently risky; so from that perspective, even if I see value in
|
By
Christos G. Psarras
·
#28327
·
|
|
moderated
Re: Changing email address security issue
#misc
I think removing it is getting more “votes“ here than keeping it.
--
J
Messages are the sole opinion of the author, especially the fishy ones.
My humanity is bound up in yours, for we can only
I think removing it is getting more “votes“ here than keeping it.
--
J
Messages are the sole opinion of the author, especially the fishy ones.
My humanity is bound up in yours, for we can only
|
By
J_Catlady
·
#28326
·
|
|
moderated
Re: Changing email address security issue
#misc
My opinion: someone not part of the groups.io support team should not be able to change a member's email address, even if that member is only a member of that one group, and even if it's a premium
My opinion: someone not part of the groups.io support team should not be able to change a member's email address, even if that member is only a member of that one group, and even if it's a premium
|
By
JohnF
·
#28325
·
|
|
moderated
Re: Changing email address security issue
#misc
Yes, it is...and will remain so, as long as the "email me a link" sign-in function exists in tandem with the "change someone else's email address."
Honestly, I've been aware of this as a potential
Yes, it is...and will remain so, as long as the "email me a link" sign-in function exists in tandem with the "change someone else's email address."
Honestly, I've been aware of this as a potential
|
By
Bruce Bowman
·
#28324
·
|
|
moderated
Re: Changing email address security issue
#misc
Yes. And isn't the basis of the whole take-over-someone's-group scenario that Mark originally posted about based on exactly that? Or I'm missing something here.
--
J
Messages are the sole opinion
Yes. And isn't the basis of the whole take-over-someone's-group scenario that Mark originally posted about based on exactly that? Or I'm missing something here.
--
J
Messages are the sole opinion
|
By
J_Catlady
·
#28323
·
|
|
moderated
Re: Changing email address security issue
#misc
Good point! So only premium group owners can hack people's accounts. ;)
--
J
Messages are the sole opinion of the author, especially the fishy ones.
My humanity is bound up in yours, for we can
Good point! So only premium group owners can hack people's accounts. ;)
--
J
Messages are the sole opinion of the author, especially the fishy ones.
My humanity is bound up in yours, for we can
|
By
J_Catlady
·
#28322
·
|
|
moderated
Re: Changing email address security issue
#misc
Correct.
Currently, a Premium group Owner can change any group member's address, log out, and subsequently request a login link to that address. That being so, anyone with $20 in their pocket and a
Correct.
Currently, a Premium group Owner can change any group member's address, log out, and subsequently request a login link to that address. That being so, anyone with $20 in their pocket and a
|
By
Bruce Bowman
·
#28321
·
|
|
moderated
Re: Changing email address security issue
#misc
There is no way for anyone, including me, to ever get your Groups.io password.
Mark
Additionally, only *premium* group owners have the ability to change email addresses. Ordinary group owners have
There is no way for anyone, including me, to ever get your Groups.io password.
Mark
Additionally, only *premium* group owners have the ability to change email addresses. Ordinary group owners have
|
By
D R Stinson
·
#28320
·
|
|
moderated
Re: Changing email address security issue
#misc
If they have your email address (assuming it’s really one of their own)they can request a login link and set one up. Right?
--
J
Messages are the sole opinion of the author, especially the fishy
If they have your email address (assuming it’s really one of their own)they can request a login link and set one up. Right?
--
J
Messages are the sole opinion of the author, especially the fishy
|
By
J_Catlady
·
#28319
·
|
|
moderated
Re: Changing email address security issue
#misc
There is no way for anyone, including me, to ever get your Groups.io password.
Mark
There is no way for anyone, including me, to ever get your Groups.io password.
Mark
|
By
Mark Fletcher
·
#28318
·
|
|
moderated
Re: Report File -- "Content flagged as objectionable"
#suggestion
There are now activity log entries for when someone reports a message, file or photo. These show up in the group activity log as well as when viewing a member's activity log.
I didn't change how the
There are now activity log entries for when someone reports a message, file or photo. These show up in the group activity log as well as when viewing a member's activity log.
I didn't change how the
|
By
Mark Fletcher
·
#28317
·
|
|
moderated
Re: Changing email address security issue
#misc
Imagine some unsuspecting new member. They join groups.io and they (akin to the scenario in Mark’s original post here) run into some bad-actor group owner, having no idea that ANY group owner, of
Imagine some unsuspecting new member. They join groups.io and they (akin to the scenario in Mark’s original post here) run into some bad-actor group owner, having no idea that ANY group owner, of
|
By
J_Catlady
·
#28316
·
|
|
moderated
Re: Changing email address security issue
#misc
Andy,
I never said I’m not “comfortable or confident” using the feature. I don’t know where you get that. I think the feature gives groups inappropriate power over members’ groups.io
Andy,
I never said I’m not “comfortable or confident” using the feature. I don’t know where you get that. I think the feature gives groups inappropriate power over members’ groups.io
|
By
J_Catlady
·
#28315
·
|
|
moderated
Re: Changing email address security issue
#misc
> Moderators already cannot change the Role of owners.
Thanks Mark. I was made aware of that after I posted. As I commented to Bruce, keeping up with beta and GMF is much more difficult since the
> Moderators already cannot change the Role of owners.
Thanks Mark. I was made aware of that after I posted. As I commented to Bruce, keeping up with beta and GMF is much more difficult since the
|
By
D R Stinson
·
#28314
·
|
|
moderated
Re: Clarify Photo Album Owner Name
#suggestion
Hi All,
I've removed the album owner from the /photos page and instead it's now displayed when you view a specific album, on top of the cover graphic.
Cheers,
Mark
Hi All,
I've removed the album owner from the /photos page and instead it's now displayed when you view a specific album, on top of the cover graphic.
Cheers,
Mark
|
By
Mark Fletcher
·
#28313
·
|
|
moderated
Re: Add DisplayName in the "joined" notification
#suggestion
I've changed it so that for all mod notifications, we will display "DisplayName <email>" if we have it, instead of just DisplayName or email.
Thanks,
Mark
I've changed it so that for all mod notifications, we will display "DisplayName <email>" if we have it, instead of just DisplayName or email.
Thanks,
Mark
|
By
Mark Fletcher
·
#28312
·
|
|
moderated
Re: Changing email address security issue
#misc
Moderators already cannot change the Role of owners.
Thanks,
Mark
Moderators already cannot change the Role of owners.
Thanks,
Mark
|
By
Mark Fletcher
·
#28311
·
|
|
moderated
Re: Changing email address security issue
#misc
If you're not comfortable or confident in using this function then just stay clear. Nobody is forcing you to use it. Some of us find it useful and use it carefully in support of members. If the
If you're not comfortable or confident in using this function then just stay clear. Nobody is forcing you to use it. Some of us find it useful and use it carefully in support of members. If the
|
By
Andy Wedge
·
#28310
·
|
|
moderated
Re: Changing email address security issue
#misc
I ran into the need for this just yesterday and have yet to actually use it. I have a member in one of my premium groups who applied for a new membership. Because I knew who the person was, I
I ran into the need for this just yesterday and have yet to actually use it. I have a member in one of my premium groups who applied for a new membership. Because I knew who the person was, I
|
By
D R Stinson
·
#28309
·
|