EXTREMELY CRITICAL SECURITY ISSUE

  • Problem
  • Updated 7 years ago
Plurk allows users with karma of 40 or above to change their display name from something different than their user name. For example, if my username is joe123, I can change my display name to just say "Joe" once I reach 40 karma.

Unfortunately there doesn't appear to be any safeguards on this to prevent users from changing their *display name* to someone else's *username*. I was able to successfully change my display name to the username of one of my friends. See this plurk thread: http://www.plurk.com/p/uy9o

While my correct user profile will display *if* someone clicks on my profile, it is still easy to misrepresent who you are using this technique and possibly getting sensitive information by other members who have been fooled.

I would suggest that Plurk turn off the feature to change a display name immediately until a fix can be put in place.
Photo of Scott-O-Rama

Scott-O-Rama

  • 12 Posts
  • 0 Reply Likes
  • VERY concerned.

Posted 7 years ago

  • 3
Photo of Amir Salihefendic

Amir Salihefendic, Lead developer

  • 369 Posts
  • 103 Reply Likes
Official Response
Display names aren't unique and if they were they would function as nick names (which are unique). Anyway, we will take actions if this becomes a problem, but currently it functions well and users are using display names properly.