Closed Bug 629424 Opened 15 years ago Closed 15 years ago

Remove kkovash@mozilla.com from watchlists

Categories

(bugzilla.mozilla.org :: General, defect)

defect
Not set
trivial

Tracking

()

RESOLVED FIXED

People

(Reporter: dre, Unassigned)

Details

I noticed that this e-mail account still appears on notification lists when submitting bugzilla changes. Since the account is deactivated, would it make sense to remove it?
Hmm. His account has been disabled with "user no longer works for MoCo", but that should never be a reason alone for disabling a Bugzilla account. People who stop working for MoCo should have the opportunity to change the email address on their account to a non-MoCo one. If they no longer want to be involved, then the deactivation reason should be "user no longer wants to be involved". Anyway, assuming no-one is watching that address any more, I have disabled the account bugmail. If Ken asks for his account back, we can change the email address and re-enable it. Gerv
Status: NEW → RESOLVED
Closed: 15 years ago
Resolution: --- → FIXED
Definitely, the part that I was specifically interested in was just the fact that Bugzilla was reporting that it was attempting to send e-mail to an address that I know not to be valid. As for the rest, I'm not sure of the proper way to handle Bugzilla accounts for employees who are members a particular security group when they leave the company. For the metrics group in particular, you need to be in the group to see all bugs, but anyone who is CCed on a bug can see it regardless of whether they are in the group. That seems to be a hole to me (which Bugzilla might very well have a mechanism to control). If the employee participated in a bug that dealt with corporate private information such as login access to a particular machine or that contained IP addresses of requests, then when that employee leaves, they shouldn't have access to that information anymore. Hopefully, there are already policies and mechanisms in place to handle that situation, and if it wasn't handled properly in Ken's case, then we can look into correcting that.
I can't comment directly on MoCo hiring/unhiring or IT practices. But in general, I would expect people who are in receipt of company confidential information, if they are no longer employed by that company, to continue to be bound by the confidentiality agreement they signed as part of their employment. If there is some unusual reason to suspect they might not honour it (e.g. they were fired for breaking a confidentiality agreement or for hacking a server) then perhaps special measures might be taken to remove their access to confidential information. But I'd expect that to be the exception rather than the rule. Gerv
Component: Bugzilla: Other b.m.o Issues → General
Product: mozilla.org → bugzilla.mozilla.org
You need to log in before you can comment on or make changes to this bug.