D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] Request mailman configuration change;

 

On 1 February 2015 at 12:18, Brad Rogers <brad@xxxxxxxxxxxx> wrote:

Mailman warns not to use sensitive passwords for this reason. Some of

That's... An interesting security approach!

what you want would require a re-write of mailman's code. Whether or

Well - not the "no monthly reminders" bit, won't. That's a global list setting FWIR.

Also editing one of the templates might be enough, but as I say, I don't use MM myself any more to know if that's the case.

not the default should be "send monthly reminders" is debatable, but if
it gets changed, I'll guarantee there'll be some broo-hah-hah about it
- *even if it's debated on list first*. In any case, any service that
can email you your password, whether encrypted or not, ought to be
considered suspect. Facebook, for example, does not email you a copy
of your password, they send a link to your registered email address
to reset it. It's encrypted with a one way cypher for that very reason.

Yep, exactly. Transmission of passwords should not be considered acceptable.Â
Â
For the next version of mailman (v3) I understand that the ability to
send password reminders is to be dropped.

I had somewhat assumed Mailman was abandoned. Having just checked the site, I'm shocked to hear a new version was released only 3 days ago. Maybe there is life in that old dog yet.


-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq