D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

[LUG] Request mailman configuration change;

 

FAO List owner / moderators;

Can I request a change in the configuration to Mailman which is running this list, please?

Every month, on the first, or what used to be called, "Mailman day" - I get an email reminding me about the list's details. (I don't need this, but also don't find it that useful)

However, this email contains my list password in plaintext.Â

Relevant bit:

================
Passwords forÂdigdilem@xxxxxxxxx:

List                  ÂPassword // URL
----Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â Â--------
list@xxxxxxxxxxxxx           ÂPLAINTEXTPASS
================

(My substitution :) ÂAlthough having a password of PLAINTEXTPASS has a certain charm )

This tells me two things:

1. That my password is stored in plaintext on the mailman server. There's been enough discussions about that to know it's not a good idea, but also I'd hope most linux users don't share this password with other, more important systems. It might not be trivial to change of course (My own Mailman system was retired late last year so I can't check)

2. That my email is being sent out, possibly in plaintext, possibly via unencrypted email. (I'm further hoping Mailman doesn't keep this as an unencrypted archive as it does other emails - unsure)

My request is that the configuration is changed to NOT include my password every month by insecure means (The recovery systems exist and are useful if I am scatterbrained to forget, I can recover them that way). If that isn't possible, I then request that the monthly reminders are turned off globally.

(Of course, I may be able to do this myself in personalised settings, but A) I find Mailman's UI irritating, and B) As I haven't touched these settings, this has to be the default setting and replicated for all list members).


I'm not asking for a change away from Mailman btw. Appalling as it's UI is, and that it is without doubt badly maintained, breaks several standards and good practice systems, that there are better, free systems out there (google groups for one) - I have a sentimental fondness for it, and I think that if it can't find a home on a linux user list of all places, it's a sad day.

(You can tell it's a Sunday and that the weather is preventing me getting out, can't you? (My hill is sheet ice again))

Simon

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq