Jump to content

Display Name on Registration Screen


Adriano Faria

Recommended Posts

  • 3 weeks later...
  • 3 weeks later...
  • 9 months later...

Adriano, I purchased this hook to use on my forums but I noticed a potential security glitch. At first, I thought it was an error with the IPS Core Suit but soon realized that it's your hook that's creating the proiblem. I hope I can explain this as clearly as I can.

Prior to installing your hook, when someone registered for an account on my forums and then opted to change their displayname through the user control panel, their userlink or profile link would only reflect their displayname, keeping their login username secret. However, after installing your hook, which I have been using for the past several months, a user on my site informed me that his login username was being display via his userlink or profilelink.

The whole idea behind keeping a login username secret while allowing members of my community to use a public username was to ensure that nobody registered on my message forums would ever have their account compromised by a hacker. It just ads some security to my community. I've since discovered that since I installed you hook, that everyone who registered after your hook was installed is affected by your hook.

At first, I thought it was a glitch in the IPS Community Suite until I realized that it's your hook that's causing the problem. Something in the way that your hook operates doesn't register as it should with the IPS Software. if you could, could you look into this?

The reason I'm bringing this to your attention is because I tested this theory out myself. One of the users who presented this problem for me registered after I installed your hook and he changed his displayname through his user control panel, even though he registered a username and a displayname with his account during the registration process. When I went into the ACP and edited his displayname, the problem was corrected. But, the fact that your hook doesn't make the distinction to use the displayname as the userlink, that it uses the "username" or the login username, that's supposed to be secret and hidden, represents a problem for anyone concerned with user account security.

Link to comment
Share on other sites

  • 7 months later...

Thanks Aiwa. I'm wanting to upgrade but if the functionality of username/display name has been removed, it's unlikely that I'll upgrade. IPS has been removing a lot of useful features since 3.0 was released and a lot of my members aren't happy about it. The choice is either to stick with IPS3 or convert to xenforo or vB, which is what I don't want to do.

Link to comment
Share on other sites

  • 8 months later...

Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...