Launchpad allows bad names as user id

Bug #254083 reported by Santiago Zarate
254
Affects Status Importance Assigned to Milestone
Launchpad itself
Fix Released
Medium
Stuart Bishop

Bug Description

Launchpad should lock "special" names... today someone added himself to the ubuntu-ve launchpad team... what got my attention was that lp allowed him to use "contactame" as lp id... which makes a very interesting issue... a user could get a ubuntu-membership and then later change his/her lp id to contactame... so his email address would be <email address hidden> (which means: <email address hidden>) and would lead to a BIG risk...

just imagine: a user comes, creates a lp account... makes himself with a ubuntu-membership, then changes his lp id to something like "<email address hidden>" or "<email address hidden>"

i suggest that "critical" words should be rejected (words in many languages... or words in the principal languages of the world...)

Revision history for this message
Christian Reis (kiko) wrote :

Can you update our blacklist to include contact*, Stuart?

Changed in launchpad:
assignee: nobody → stub
Revision history for this message
Santiago Zarate (foursixnine) wrote :

so, i guess sales, employment, and stuff are already blacklisted? do you have a public blacklist of names which cant be taken?...

Stuart Bishop (stub)
Changed in launchpad-foundations:
importance: Undecided → Medium
milestone: none → 2.2.1
status: New → Triaged
Revision history for this message
Stuart Bishop (stub) wrote :

Blacklist updated,

Changed in launchpad-foundations:
status: Triaged → Fix Released
Revision history for this message
Santiago Zarate (foursixnine) wrote : Re: [Bug 254083] Re: Launchpad allows bad names as user id

Is there a public black-list for this? so it could be improved?

Curtis Hovey (sinzui)
visibility: private → public
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.