From owner-freebsd-bugbusters@FreeBSD.ORG Sun Feb 15 02:14:42 2004 Return-Path: Delivered-To: freebsd-bugbusters@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1E72516A4CE for ; Sun, 15 Feb 2004 02:14:42 -0800 (PST) Received: from grunt24.ihug.com.au (grunt24.ihug.com.au [203.109.249.144]) by mx1.FreeBSD.org (Postfix) with ESMTP id E51C543D1D for ; Sun, 15 Feb 2004 02:14:41 -0800 (PST) (envelope-from murray_baker@ihug.com.au) Received: from p16-max2.syd.ihug.com.au (peroxide) [203.173.155.80] by grunt24.ihug.com.au with smtp (Exim 3.35 #1 (Debian)) id 1AsJIN-0007pn-00; Sun, 15 Feb 2004 21:14:40 +1100 Message-Id: <3.0.3.32.20040215211107.009dde20@pop.ihug.com.au> X-Sender: murray_baker@pop.ihug.com.au X-Mailer: QUALCOMM Windows Eudora Light Version 3.0.3 (32) Date: Sun, 15 Feb 2004 21:11:07 +1100 To: bugbusters@FreeBSD.org From: Murray Baker Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Subject: i386/62382: Web access to PRs enables harvest email addresses for spamming. X-BeenThere: freebsd-bugbusters@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Coordination of the Problem Report handling effort. List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 15 Feb 2004 10:14:42 -0000 Hi, See PR ``i386/62382''. http://www.freebsd.org/cgi/query-pr.cgi?pr=62382 Within days of submitting the update to ''i386/62382'', which has been appended to the original PR with my unmodified email address exposed, I have my first ever spams to this email address. Is this a coincidence? I know that this is a real pain, but I suggest that if email addresses are to be visible on web, they should be rendered into 'gif' or 'png' and the html then reference the bitmap. Bitmaps should use different fonts, colors, backgrounds to discourage ocr software. ``gfont-1.0.2'' will do some of the job. http://www.FreeBSD.org/cgi/url.cgi?ports/graphics/gfont/pkg-descr Examples at gfont homepage. http://www.engelschall.com/sw/gfont/example/ How many email addresses can be harvested from the complete set of PRs? http://www.freebsd.org/cgi/query-pr-summary.cgi My only defense against spam is to change email addresses frequently. Cheers, Murray.