Mailing list reminder: password is sent in the clear

Mike Shaver mike.shaver at gmail.com
Fri Jul 1 11:27:12 PDT 2011


What can someone do with that password, though? Just change your
subscription settings, afaik, so the security in place seems proportionate.

Could report it upstream to the mailman team, I suppose.

Mike
 On Jul 1, 2011 10:09 AM, "Axel Rauschmayer" <axel at rauschma.de> wrote:
> That’s a good start, thanks. Still find it a bit scary that there’s no
encryption.
>
> On Jul 1, 2011, at 16:07 , André Bargull wrote:
>
>> Log-in at [1] and remove the option to send a monthly password remainder?
>>
>>> Get password reminder email for this list?
>>> Once a month, you will get an email containing a password reminder for
every list at this host to which you are subscribed. You can turn this off
on a per-list basis by selecting No for this option. If you turn off
password reminders for all the lists you are subscribed to, no reminder
email will be sent to you.
>>>
>>
>>
>> [1] https://mail.mozilla.org/options/es-discuss
>>
>>> Can this be fixed? I’ve already sent feedback, but didn’t get a
response.
>>>
>>> Preferably, passwords would also be encrypted for storage.
>>>
>>> --
>>> Dr. Axel Rauschmayer
>>> axel at rauschma.de
>>> twitter.com/rauschma
>>>
>>> Home: rauschma.de
>>> Blog: 2ality.com
>
> --
> Dr. Axel Rauschmayer
> axel at rauschma.de
> twitter.com/rauschma
>
> Home: rauschma.de
> Blog: 2ality.com
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.mozilla.org/pipermail/es-discuss/attachments/20110701/451b4585/attachment.html>


More information about the es-discuss mailing list