On Fri, Jul 1, 2011 at 2:50 PM, Mike Samuel <[email protected]> wrote: > 2011/7/1 Mike Shaver <[email protected]>: >> On Fri, Jul 1, 2011 at 2:30 PM, Mike Samuel <[email protected]> wrote: >>> 2011/7/1 Mike Shaver <[email protected]>: >>>> What can someone do with that password, though? Just change your >>>> subscription settings, afaik, so the security in place seems proportionate. >>>> >>>> Could report it upstream to the mailman team, I suppose. >>> >>> Use it to do a better job of impersonating. Try it out on other sites. >> >> I don't understand how you could impersonate better, could you >> explain? You can send mail with any From: you want without bothering >> to go through someone's mailman account, and you can't even send mail >> from the mailman interface! >> >> Since mailman passwords are randomly generated at subscription time >> (and virtually never changed), password reuse is pretty unlikely. > > Can't a mailman account holder associate a public key with a mailman instance?
Not in stock mailman (http://www.gnu.org/s/mailman/features.html), but there is a fork which permits it, I think. Mike _______________________________________________ es-discuss mailing list [email protected] https://mail.mozilla.org/listinfo/es-discuss

