[wp-trac] [WordPress Trac] #60843: Hiding the username

WordPress Trac noreply at wordpress.org
Tue Mar 26 11:28:19 UTC 2024


#60843: Hiding the username
-----------------------------+------------------------------
 Reporter:  Clivesmith       |       Owner:  (none)
     Type:  feature request  |      Status:  new
 Priority:  normal           |   Milestone:  Awaiting Review
Component:  Users            |     Version:
 Severity:  normal           |  Resolution:
 Keywords:  close            |     Focuses:
-----------------------------+------------------------------
Changes (by swissspidy):

 * keywords:  changes-requested => close
 * focuses:  administration =>


Comment:

 Hi there and welcome to WordPress Trac!

 The display name is used for things like showing your actual full name in
 blog posts or author archives. It's not supposed to replace the username
 or "hide" the username.

 > I thought that the displayname would have hidden the real username from
 people trying to break into the system.

 The WordPress project doesn’t consider usernames or user ids to be private
 or secure information. A username is part of your online identity. It is
 meant to identify, not verify, who you are saying you are. Verification is
 the job of the password.

 See https://make.wordpress.org/core/handbook/testing/reporting-security-
 vulnerabilities/#why-are-disclosures-of-usernames-or-user-ids-not-a
 -security-issue

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/60843#comment:1>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list