Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN Emails - Security Faux PasDNN Emails - Security Faux Pas
Previous
 
Next
New Post
11/18/2010 4:18 AM
 
Be aware that if you forward the latest marketing email regarding DNN 5.6 to someone, and they then click on the Enterprise Link, and from the page presented then click on the "Pricing" link that will take them to a form prepopulated with your personal details such as address and phone etc obtained from your profile EVEN THOUGH you are not the person requesting the page.
It seems my identity is embedded in the email and the information is presented with confirming who is requesting the page by requesting a sign in.
I understand it is an attempt to make life easier but this does not say much about the approach of the DNN team to data security.
Or am I being paranoid??
 
New Post
11/18/2010 5:23 AM
 
Julian Horn wrote:
...
Or am I being paranoid??

Not at all!( Or at least I am as paranoid as you.)
Thank you for bringing this to attention.

 
New Post
11/18/2010 6:14 AM
 
I believe the mail simply has an encrypted cipertext of the email account it's been sent to in the link (essentially an ecncrypted form of somepage.aspx?email=myemail@email.com). When the page loads, the email is decrypted and the details are populated for that email address if details have been provided to the marketing system before (we use a 3rd party product which uses unique email address's as a key, unlike dotnetnuke)

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
New Post
11/18/2010 6:35 AM
 
Whatever the method used it discloses: First Name, Last Name, Email, Phonenumber, Company, Country, Employees, Products I use and whether I want a DNN sales person to contact me.
I suspect it could - if I had given it - also disclose my project budget and timescale.
This is information I disclosed to DNN and did not expect to be visible in this way. Agreed it only happens if I forward the personalised email but what if that gets forwarded on etc.
Forms should never be prepopulated unless the user has positively signed in to a website. Basic security I would have said.
 
New Post
11/18/2010 8:02 AM
 
I appreciate your concerns and will be forwarding this onto the sales team to make them aware of this.

Buy the new Professional DNN7: Open Source .NET CMS Platform book Amazon US
 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...DNN Emails - Security Faux PasDNN Emails - Security Faux Pas


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out