[tor-talk] misconfigured mailing list (mailman software) for torproject discloses passwords in plaintext (stores too?)

Matthew Fisch mfisch at mfisch.com
Fri Nov 9 23:09:36 UTC 2012


Upon signing up for the mailing list on the list server, my password was emailed to me in plaintext. In the year 2012 this is extremely bad security practice. At the very least the sign-up page should warn users to make the password unique.

The password may also be stored in reverseable format.

I used a unique random password for this mailing list, I'm going to guess however a significant portion of the mailing list either uses this password in other locations, a significant subset of them probably can't trust their mailbox to be secure.

Thanks,
Matt

Matthew Fisch
mfisch at mfisch.com



More information about the tor-talk mailing list