You'd have to hide the profiles as well since it's easy enough to go through the userids and find the user names. And even if you did that, you could get the usernames of everyone who posted by reading the forum.
Is this a poll about whether vbulletin.org should have a membership list (if so, it is in the correct forum) or about whether any site should have a membership list available to guests/users/anyone (in which case, it is in the wrong forum)?
I know we can't avoid them making a list from posts - it just seems like making an ordered list available - so easy for everyone to access- makes little sense.
I know we can't avoid them making a list from posts - it just seems like making an ordered list available - so easy for everyone to access- makes little sense.
Yeah, I see what you're saying, and I can't really think of a use for it (except to search for a user when you can't remember the name exactly). But I kind of doubt that it would stop these kinds of attacks.
Yeah, I see what you're saying, and I can't really think of a use for it (except to search for a user when you can't remember the name exactly). But I kind of doubt that it would stop these kinds of attacks.
hmmm idk -having this latest attack going on alphabetically - I predict just a few more posts from the D peeps tomorrow
hmmm idk -having this latest attack is going on alphabetically - I predict just a few more emails from the D peeps tomorrow
Yeah, I agree that they most likely did get the names from the member list, I just think if it wasn't available and someone wanted to to look for passwords on this site, they'd just get the names another way. I could be wrong.
One thing that's interesting to me is that I've never heard of this happening on other sites (although I don't claim to have that kind of knowledge of a lot of forums), and even though it happens here every few months I haven't seen a lot of evidence of accounts being hacked.
Yeah, I agree that they most likely did get the names from the member list, I just think if it wasn't available and someone wanted to to look for passwords on this site, they'd just get the names another way. I could be wrong.
One thing that's interesting to me is that I've never heard of this happening on other sites (although I don't claim to have that kind of knowledge of a lot of forums), and even though it happens here every few months I haven't seen a lot of evidence of accounts being hacked.
Haven't had it happen to my site either - and it is great that vB has the built-in timeout if it does happen. I still think hiding it from guests may help to avoid some future skiddie attacks and save a few future "My account is under attack threads."
The members list doesn't really serve a grand purpose most of the time. There are some limited cases for it being useful. As long as the admin/staff can find users, I don't think its all that great.
In vB2/3/4 it can be one of the most intensive functions of the software, esp when you have a large user base.