<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: e-mails</title>
	<atom:link href="http://habitablezone.com/2011/04/25/179/feed/" rel="self" type="application/rss+xml" />
	<link>https://habitablezone.com/2011/04/25/179/</link>
	<description></description>
	<lastBuildDate>Sun, 19 Apr 2026 04:50:17 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Eri</title>
		<link>https://habitablezone.com/2011/04/25/179/#comment-122</link>
		<dc:creator>Eri</dc:creator>
		<pubDate>Wed, 27 Apr 2011 13:06:06 +0000</pubDate>
		<guid isPermaLink="false">http://habitablezone.com/?p=179#comment-122</guid>
		<description>Yes, I can.  You have no idea what I went through that time Bowser wanted to donate to the site and I volunteered to be his go-between.  It was ridiculously funny.  I had to wonder if Bows was actually some high mucky-muck but still...  I mean I have an e-mail address at mail.com that absolutely no one could ever guess is mine by the address.</description>
		<content:encoded><![CDATA[<p>Yes, I can.  You have no idea what I went through that time Bowser wanted to donate to the site and I volunteered to be his go-between.  It was ridiculously funny.  I had to wonder if Bows was actually some high mucky-muck but still&#8230;  I mean I have an e-mail address at mail.com that absolutely no one could ever guess is mine by the address.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Robert</title>
		<link>https://habitablezone.com/2011/04/25/179/#comment-108</link>
		<dc:creator>Robert</dc:creator>
		<pubDate>Tue, 26 Apr 2011 23:12:17 +0000</pubDate>
		<guid isPermaLink="false">http://habitablezone.com/?p=179#comment-108</guid>
		<description>How about now? 

Looks like you guys found a hole in WordPress. It&#039;s hard to imagine something so blatant slipping by, except that WP is really intended for single-blog use. OTOH it supports multiple authors and public commenting via captchas, so right away there&#039;s a potential for disclosing email addresses. 

I managed to close the hole by suppressing display of comments in the editor completely. That&#039;s an imperfect solution because it means that editors can&#039;t approve pending comments, i.e. those posted by the public via a captcha. I&#039;m pretty sure that personal info needs to be restricted to a higher level than editors, aka moderators, because using Bowser as our privacy canary in the coal mine, can you imagine the brick he&#039;d excrete if Frank could see his email address?</description>
		<content:encoded><![CDATA[<p>How about now? </p>
<p>Looks like you guys found a hole in WordPress. It&#8217;s hard to imagine something so blatant slipping by, except that WP is really intended for single-blog use. OTOH it supports multiple authors and public commenting via captchas, so right away there&#8217;s a potential for disclosing email addresses. </p>
<p>I managed to close the hole by suppressing display of comments in the editor completely. That&#8217;s an imperfect solution because it means that editors can&#8217;t approve pending comments, i.e. those posted by the public via a captcha. I&#8217;m pretty sure that personal info needs to be restricted to a higher level than editors, aka moderators, because using Bowser as our privacy canary in the coal mine, can you imagine the brick he&#8217;d excrete if Frank could see his email address?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
