Make WordPress Core

Opened 9 months ago

Closed 9 months ago

#60843 closed feature request (wontfix)

Hiding the username

Reported by: clivesmith's profile Clivesmith Owned by:
Milestone: Priority: normal
Severity: normal Version:
Component: Users Keywords: close
Focuses: Cc:

Description

A user has a username, there is also a nickname and a displayname. Why is there a displayname when when the username is shown in the browser on the bottom left ?
I thought that the displayname would have hidden the real username from people trying to break into the system.
Can the system be changed to use the displayname as the path it shows in the link?.

Change History (3)

#1 @swissspidy
9 months ago

  • Focuses administration removed
  • Keywords close added; changes-requested removed

Hi there and welcome to WordPress Trac!

The display name is used for things like showing your actual full name in blog posts or author archives. It's not supposed to replace the username or "hide" the username.

I thought that the displayname would have hidden the real username from people trying to break into the system.

The WordPress project doesn’t consider usernames or user ids to be private or secure information. A username is part of your online identity. It is meant to identify, not verify, who you are saying you are. Verification is the job of the password.

See https://make.wordpress.org/core/handbook/testing/reporting-security-vulnerabilities/#why-are-disclosures-of-usernames-or-user-ids-not-a-security-issue

#2 @Clivesmith
9 months ago

Hi, OK thanks for telling me, I will use a pluging to hide the username.

#3 @swissspidy
9 months ago

  • Milestone Awaiting Review deleted
  • Resolution set to wontfix
  • Status changed from new to closed
Note: See TracTickets for help on using tickets.