There has been an accusation that an email address on comments on this site has been misused. I looked into the matter and here are the results:
- The man accused of misusing the confidentiality of a commenter’s email address has no recollection of the event.
- The man who accused the misuse does not have the email which he claims was sent over a year ago.
Firstly, I want to state that the email field is required in order to submit a comment. However, the plugin does not require the validation of the email address in order to post the comment. This means that “nobody@nobody.com” is a “valid” email address for the plugin. The email address is used as a means for the plugin to moderate comments. If an email has been previously approved, future comments will be approved if other conditions for validation are met.
Note: the above email example will not be approved for comments since Crazy Ed would use it to bypass comment validations.
Back to the point of this post, please use operational security here and if you feel safer, use a fake email account. Keep in mind that this would require your new email account to be verified for the first comment. As for this particular incident, there is no way for me to prove or disprove the allegation. I have implemented some changes to mitigate this from happening in the future.
David DeGerolamo