addressbook file contains infomation about deleted people if duplicate people are created

RESOLVED WONTFIX

Status

--
major
RESOLVED WONTFIX
17 years ago
14 years ago

People

(Reporter: bugzilla, Assigned: cavin)

Tracking

({privacy})

Trunk
mozilla1.4alpha
x86
Windows 2000
privacy

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [adt2])

(Reporter)

Description

17 years ago
I just deleted all entries in the addressbook except one and exited Mozilla. 
But if I look at the abook.mab file with a text editor I can see that it still 
contains information about all the deleted people.
A true privacy issue!

Here's how to reproduce:
1. start mozilla with a fresh and clean profile
2. start the addressbook without creating a mail account, just hit cancel and 
then exit in the account creation dialog.
3. create a person with First = "First", Last = "Last", Mail = "Mail@mail.mail"
4. create a second person with the same info. First = "First", Last = "Last", 
Mail = "Mail@mail.mail"
5. delete both persons and exit mozilla
6. look at the file abook.mab with a fileeditor. It contains the all the 
information about the person!!!!

Having duplicated persons and deleting people, doesn't "really" delete the 
people!

build 20020104
(Reporter)

Updated

17 years ago
Keywords: privacy

Comment 1

17 years ago
Marking nsbeta1 since the user will expect the data to be deleted. Isn't this a 
privacy issue?
Keywords: nsbeta1

Comment 2

17 years ago
I think this may be a dup of one of our bugs about not being able to compact the
address book.
Keywords: nsbeta1 → nsbeta1-

Comment 3

17 years ago
Marking nsbeta1. When entries are deleted from the UI then those changes should
be reflected in the file itself. It's also a privacy issue.
Keywords: nsbeta1- → nsbeta1

Comment 4

16 years ago
Mail triage team: nsbeta1+/adt2
Keywords: nsbeta1 → nsbeta1+
Whiteboard: [adt2]
(Assignee)

Comment 5

16 years ago
Reassigning.
Assignee: racham → cavin
(Assignee)

Updated

16 years ago
Target Milestone: --- → mozilla1.4alpha
I'm not sure I agree this is a privacy issue.

if you can get to my abook.mab, you can do anything you want anyways.

why does it matter that deleted items aren't purged?

note, the same could be said about deleted mail in a local mail file, which
doesn't get removed until we compact.

we do have bugs on allowing for compaction of addressbooks, but I don't think we
want to undertake that risk right now.

Comment 7

16 years ago
Mail triage team: nsbeta1-
Keywords: nsbeta1+ → nsbeta1-
actually, won'tfix.

the deleted cards are kept around on purpose, for absync / palm sync purposes.

I know this, because it caused a regression, see #198303

and, as I said before, the same could be said about deleted mail in a local mail
file, which doesn't get removed until we compact.
Status: NEW → RESOLVED
Last Resolved: 16 years ago
Resolution: --- → WONTFIX
Product: Browser → Seamonkey
You need to log in before you can comment on or make changes to this bug.