[tor-talk] misconfigured mailing list (mailman software) for torproject discloses passwords in plaintext (stores too?)

andrew at torproject.is andrew at torproject.is
Sat Nov 10 01:25:03 UTC 2012


On Fri, Nov 09, 2012 at 06:09:36PM -0500, mfisch at mfisch.com wrote 0.7K bytes in 16 lines about:
: Upon signing up for the mailing list on the list server, my password was emailed to me in plaintext. In the year 2012 this is extremely bad security practice. At the very least the sign-up page should warn users to make the password unique.

Right. This is the default mailman process. Getting mailman to improve
their defaults hasn't worked so far.

: The password may also be stored in reverseable format.
: 
: I used a unique random password for this mailing list, I'm going to guess however a significant portion of the mailing list either uses this password in other locations, a significant subset of them probably can't trust their mailbox to be secure.

A significant number of people join via email, not the web interface,
and therefore mailman picks a password for them.

What's more secure mailing list software that is in debian repos and works
for non-technical users?

-- 
Andrew
http://tpo.is/contact
pgp 0x6B4D6475


More information about the tor-talk mailing list