Patches for Release #67

Jul 22, 2010 09:45

1. Users who have renamed to an account that was in use previously (that is, an account that was purged and then purchased as a rename) will be unable to use OpenID on external sites. This is a temporary fix to a security problem and we'll update here when it's fixed ( Read more... )

openid, stats and ratings, r67, release #67

Leave a comment

Comments 28

rebelsheart July 22 2010, 16:54:57 UTC
will this affect the people missing stats from a week or so ago?

Reply

nickygabriel July 22 2010, 17:01:52 UTC
I would like to know that too!

Reply


rebelsheart July 22 2010, 17:02:25 UTC
the error message you get when you try to use OpenID and have renamed is very straightforward and clear, but is not displayed on a page in any of LiveJournal's styles. There's nothing to suggest you've reached a legitimate LiveJournal page.

Reply


matgb July 22 2010, 17:25:58 UTC
This is a temporary fix to a security problem and we'll update here when it's fixed.

Am actually discussing something related to this elsewhere, is this a problem LJ specific or is it related to the new owner of the name getting to login elsewhere as if they're the previous owner?

Specifically related to DW, but I also have a few other accounts linked to my OpenID, and have given access to LJ based OpenID accounts elsewhere.

Reply

pseudomonas July 29 2010, 10:38:13 UTC
Yes, I'd like to know this as well.

Reply


the_cynic July 22 2010, 18:22:12 UTC
1) Is not quite correct. I renamed (5 years ago) to my current name which was a never-before-used name and still am affected by the OpenID issue.

Reply

marta July 22 2010, 18:23:42 UTC
I've sent you some info - your name was in use before :)

Reply

alexey_dukov August 4 2010, 06:31:46 UTC
khm...

Reply

miquel_fire July 23 2010, 12:35:41 UTC
And I'm in the same boat.

Reply


evila_elf July 23 2010, 08:04:09 UTC
If there is a username that we are waiting for that hasn't yet been purged, what is considered the wait time? Account hasn't been used since 2001 and there are 0 posts.

Reply

daluci July 23 2010, 12:57:45 UTC
As far as I know, inactive accounts aren't being purged right now, just suspended ones.

Reply


Leave a comment

Up