0 FAMILY SECURITY PROBLEM 3 Michael Manning posted 5 Years Ago We do not require creating a login to perform an event registration. Our event registration also allows the registrant to register other people even if they are non-family members. The "is this a family member" is defaulted to "yes" and is usually never touched by the registrant which means anyone they register for an event become part of their family. We've tried the "Ask" selection as well but's it's usually left as "yes" which again means the person is automatically put in the registrants family.Those people then show as "Pending" and I mark them as "Active" and I have no knowledge if the family they are in is correct or not.And this brings me to my big security concern that I found by testing can happen.For example Judy Simpson registered her daughter Andrea Simpson and a neighbor Dani Kiner for an event and didn't pay much attention to the family status and now both Andrea Simpson and Dani Kiner are listed as part of Judy Simpson's family. They show as Pending and I change them to Active.One week later, Dani Kiner decides to register for a web user id.As a Rock admin I see Dani Kiner as a new "Pending" and it matches to an "Active" record which is the one previously entered by Judy Simpson. The natural course of action is to merge the new Pending to the Current Active. Since Dani Kiner is a part of Judy Simpson's family, right or wrong, she nows has a web login and with the login clicks on Account information and can see any and all family members in the Simpson family as well as Giving information etc...I personally believe this is big security problem but given the circumstances, anyone have suggestions.