[tor-bugs] #34256 [Internal Services/Tor Sysadmin Team]: jerks using our mailman to spam people

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed May 20 19:08:20 UTC 2020


#34256: jerks using our mailman to spam people
-------------------------------------------------+---------------------
 Reporter:  arma                                 |          Owner:  tpa
     Type:  defect                               |         Status:  new
 Priority:  Medium                               |      Milestone:
Component:  Internal Services/Tor Sysadmin Team  |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:                                       |  Actual Points:
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+---------------------

Comment (by anarcat):

 Replying to [ticket:34256 arma]:
 > Maybe we can hack mailman to discard attempts that include a two-word
 name?

 That could be difficult, but I've patched Mailman before. it might be
 doable. Not sure if it would work, and might catch a lot of false-
 positives...

 > Is there some way to moderate the subscription attempts?

 There is. I'm not sure if it happens before or after the email
 confirmation however. But there's definitely a way to make list moderators
 approve new members.

 > Do we even want that?

 That would possibly be a huge pain in the back for moderators.

 > Maybe we should disable email subscription interactions with mailman
 entirely?

 That might be more reasonable... but then again, if those attempts come by
 email, from a botnet, why aren't we blocking *those* emails instead? seems
 to me they should be on some block list already?

 maybe we could check if they are on spamhaus or some list eventually...

 i wonder if upgrading to mailman 3 could fix this problem... we'll have to
 do it eventually anyways because of the death of python 2 (#33949).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/34256#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list