# How can I protect my app’s user profiles?

**URL:** https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980
**Category:** Report a Bug
**Created:** [December 17, 2020, 9:19am UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980 "2020-12-17T09:19:10Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![maschera](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maschera/32/6730_2.png) [@maschera](https://community.glideapps.com/u/maschera)
#### Post date: [December 17, 2020, 9:19am UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/1 "2020-12-17T09:19:10Z")

</div>

A random person online has downloaded my full user database right after receiving access to my app.

He sent me the list of my users in a txt file - I was literally shocked.

Thank God it doesn’t seem to appear “ransomware” but more of a lead gen tactic - he wants to sell me cyber security services.

After a bit of research and chatting with a technical friend, he told me that he might have performed UserEnum tactics to reverse engineer all my sign-ups. He has also told me that this issue could be solved by applying a patch.

I understand that Wordpress is vulnerable to UserEnum by default (unless you apply some plugins), however this shouldn’t happen.

@Glide Team - I have the exact string that the hacker used to download the list. Please let me know if you need it and please let’s fix this key vulnerability.

---

<div class="post-metadata">

### Author: ![MaxB](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maxb/32/15623_2.png) [@MaxB](https://community.glideapps.com/u/MaxB)
#### Post date: [December 17, 2020, 11:05am UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/2 "2020-12-17T11:05:25Z")

</div>

So he got access to all the database?

That’s bad.

---

<div class="post-metadata">

### Author: ![SantiagoPerez](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/santiagoperez/32/16807_2.png) [@SantiagoPerez](https://community.glideapps.com/u/SantiagoPerez)
#### Post date: [December 17, 2020, 11:55am UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/3 "2020-12-17T11:55:54Z")

</div>

Were you using any of the security measures that the Glide team has developed to protect the database???

---

<div class="post-metadata">

### Author: ![maschera](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maschera/32/6730_2.png) [@maschera](https://community.glideapps.com/u/maschera)
#### Post date: [December 17, 2020, 12:47pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/4 "2020-12-17T12:47:29Z")

</div>

Yes, the full list of registered users - their emails, basically.

---

<div class="post-metadata">

### Author: ![maschera](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maschera/32/6730_2.png) [@maschera](https://community.glideapps.com/u/maschera)
#### Post date: [December 17, 2020, 12:53pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/5 "2020-12-17T12:53:34Z")

</div>

What security measures?

Shouldn’t protecting our database a default measure?

I cannot locate any except from anonymising email addresses. And I’m not sure this would work for me and my users.

There are [plugins](https://wordpress.org/plugins/stop-user-enumeration/) for Wordpress to avoid UserEnum.

---

<div class="post-metadata">

### Author: ![Rosewebstudio](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/rosewebstudio/32/12261_2.png) [@Rosewebstudio](https://community.glideapps.com/u/Rosewebstudio)
#### Post date: [December 17, 2020, 1:16pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/6 "2020-12-17T13:16:43Z")

</div>

@maschera[Glide Docs](https://docs.glideapps.com/all/reference/security-and-per-user-data/row-owners)

> [@lock Row Owners](https://community.glideapps.com/t/row-owners/4927):
>
> We just rolled out a new security feature we call Row Owners. It will give your users more security and allows you to keep confidential data in Glide. If your users keep personal data in Glide, please use Row Owners: If you want some more context, this has been discussed here on the forum:

[Support@glideapps.com](mailto:Support@glideapps.com)

---

<div class="post-metadata">

### Author: ![david](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/david/32/62831_2.png) [@david](https://community.glideapps.com/u/david)
#### Post date: [December 17, 2020, 1:28pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/7 "2020-12-17T13:28:22Z")

</div>

Please use Row Owners to protect which rows can be downloaded, including your user profiles.

Can you forward us the information you were sent, so we can review it?

---

<div class="post-metadata">

### Author: ![maschera](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maschera/32/6730_2.png) [@maschera](https://community.glideapps.com/u/maschera)
#### Post date: [December 17, 2020, 1:29pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/8 "2020-12-17T13:29:26Z")

</div>

Thanks Jason.

I have enabled this, although I’m not sure it solves my issue.

---

<div class="post-metadata">

### Author: ![Jeff\_Hager](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/jeff_hager/32/43_2.png) [@Jeff\_Hager](https://community.glideapps.com/u/Jeff_Hager)
#### Post date: [December 17, 2020, 2:18pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/9 "2020-12-17T14:18:07Z")

</div>

More info

[https://docs.glideapps.com/all/guides/security-center](https://docs.glideapps.com/all/guides/security-center)

---

<div class="post-metadata">

### Author: ![maschera](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/maschera/32/6730_2.png) [@maschera](https://community.glideapps.com/u/maschera)
#### Post date: [December 17, 2020, 2:43pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/10 "2020-12-17T14:43:52Z")

</div>

Ok - I have just sent it you via chat.

---

<div class="post-metadata">

### Author: ![Pablo\_books](https://sea2.discourse-cdn.com/flex002/user_avatar/community.glideapps.com/pablo_books/32/2110_2.png) [@Pablo\_books](https://community.glideapps.com/u/Pablo_books)
#### Post date: [December 17, 2020, 5:13pm UTC](https://community.glideapps.com/t/how-can-i-protect-my-app-s-user-profiles/19980/11 "2020-12-17T17:13:29Z")

</div>

Aw man, that’s freaky. Hope you were using virtual email addresses!
