#4 under the security tab for the list check the "Disable List Command" Checkbox
Eric S ----- Original Message ----- From: "Marc Funaro" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, September 05, 2002 11:49 AM Subject: RE: [IMail Forum] trailers, and hiding addresses > 1. The article I referenced explains WHY the original sender's email > address appears in the messages that everyone receives, and that there is no > way to "hide" it, at least not within the scope of an iMail setting. See > item FOUR below for more. > > 2. NO, I did *not* mean "not being able to NOT include it (the trailer > text)". I meant exactly what I said -- if I create a trailer, the manual > says it will NOT appear at the bottom of messages that are delivered to > accounts ON the iMail server. The trailer also does not appear in HTML > messages, for the obvious reasons I was already aware of (it would have to > be inserted before the ending HTML tags of an HTML message). My frustration > lies in the fact that this so called "freebie" (which is promoted in the > sales materials for iMail) feature has so many restrictions... can't use > with HTML, can't expect it to show up at the bottom of messages delivered to > local accounts (which is what an IpSwitch manual said -- I will test this > again to see for myself). > > Bottom line, I need a way to include text at the bottom of ALL list > messages, regardless of format or location of the destination mail > accounts... That's what I am asking for. If it means having the list server > strip HTML tags first, or if it means having the list server "know" how to > place my requested trailer at the bottom of an incoming HTML message, or if > it means I create TWO trailers -- one in plain text, the other in HTML... > with this mature a product, I don't think it's too much to ask in a current > or near-future release. And if this is not something that the "majority" of > list servers support (I don't care about the majority, I care about the one > I purchased, which says it supports trailers), this appears to be an > opportunity for IpSwitch to offer something the others don't. HTML/Rich > Text messages are a fact of life, and more to the point are implemented > features by MANY internet users, and server products should keep up with > that. > > 3. Being a good citizen has little to do with whether or not one sends an > email message in plain text or HTML. Yes, I fully understand that HTML has > higher overhead, but you're burying your head in the sand if you think that > this sometimes useful way of transmitting well-formatted messages (how about > tables that some users wish to present in their messages, without having to > do an attachment? An attachment typically has more overhead than an HTML > message that serves the same purpose. How about automatically generated > HTML invoices? etc. etc.) doesn't have it's place, even on a listserv. > > You don't know my users, you don't know our particular use of the list, and > so it stands to reason that you shouldn't pass judgement on the "good > citizenship" of our users. We don't even USE digest mode on the list in > question, and HTML messages are useful part of what we are doing -- plus, > it's user-friendly, and I don't have to train a bunch of users (and remind > them like a mother hen) on how to turn off HTML in their mail programs JUST > for our list. Rejecting HTML messages is not an option, nor do we wish to. > Please -- don't beat the HTML vs. Text message drum around me... it's an > elitist, irrelevant argument; each format most certainly has its place > online, even on mailing lists. I will try in the future to respect this > list's requests for plain-text messages. > > 4. My claim that list member's email addresses are NOT private (in other > words, any list member can discover the email addresses of all other list > members on a MODERATED, "PRIVATE" list) is not an "allegation", it's a > tested frickin' fact. I have a moderated list on my iMail server. It is > marked "private" (it disallows subscriptions). I can send a plain text > email to [EMAIL PROTECTED], with "list LISTNAME" in the body of the > message, and I'll get back a list of all that list's member's email > addresses -- JUST LIKE THE MANUAL SAYS -- even if I check the box on the > list's "SECURITY" tab (the name of the tab prompting me to believe I can > secure the list, including members addresses... silly me) labeled "Disable > List Command". Sandy, I HAVE tested this -- the email addresses are > available to all list members who know how to issue that command via email, > even with the checkbox checked on a moderated, Private List (that checkbox > is also checked). In addition, the article I mentioned also demonstrates > how list member email addresses can be discovered, just by reading the > messages to the list using certain email clients. So, my claim stands -- > there is no real way to secure or "hide" the email addresses of list > members. What is so perplexing about wanting to keep list member's email > addresses private, especially when they can be delivered in BULK to anyone > who knows the LIST command? Can you say SPAM?? > > I am fully willing to admit that I could be missing a setting or > misunderstanding existing settings... but please don't accuse me of not > testing my claims before asking for assistance. > > Frankly, I consider the fact that the email addresses of all of a list's > members is available using the LIST command, even with the "Disable LIST > command" checkbox checked, somewhat of a security hole, if only to allow > malicious list members to discover and use the available email addresses for > SPAMMING purposes. The additional availability of a list member's email > address through each post is a little less obvious, and does not occur with > all mail readers, but could still be used in a similar way, albeit with a > lot more harvesting work. > > It would almost seem better if the "reply to list" feature, when enabled, > would remove the email address of the sender from the email before sending > it out to the list, replacing anything containing the sender's email address > in the header with the email address of the list. This would disallow > members from replying to one another, and prevent them from discovering the > email addresses of other list members. > > Perhaps you're right... I'm asking for some features in something that maybe > the majority of you consider to be a "freebie" feature. But hell, this > "freebie" IS a listed, marketed feature in the iMail sales materials > (http://www.ipswitch.com/products/IMail_Server/listserver.html). I think > that justifies my comments on above issues at least to some extent. By the > way -- check the 6th bullet point of that features page... "Disable" should > mean "Disable"!! > > Thanks for listening to my rant. > > > > > > > > > http://support.ipswitch.com/kb/IM-20000922-DM01.htm > > What on earth did you find in there that's relevant to your questions? > > > This trailer feature for the iMail list server is practically > > useless -- not being able to include it at the bottom of all > > messages sent to local accounts makes NO sense at all > > Did you mean "not being able to NOT include it"? I have to say, this > missing advanced feature is also missing from the majority of list > managers out there, so it makes its own kind of sense. Or did you mean > something else, like the global trailer.txt feature (which isn't part > of IMAILSRV)--this is, I agree, a strange implementation, but not in > the same realm. > > > and if users are using HTML formatting (99% of our users do!), the > > trailer won't appear. > > As Rod said, good citizens use plain-text for lists, which generate an > explosive (no pun intended) amount of traffic and so must be treated > especially delicately. If you can't convince them by moderator message > alone, convince them by rejecting messages that have > 'multipart-alternative' in the headers, etc. IMAILSRV is part of the > MTA part of IMail, which does not speak HTML. True, it would be great > if it did do this kind of tag-stripping thing on its own, but it is > basically a "freebie" thrown in alongside more maintained modules. > > > What can be done to REALLY add a trailer, without all these silly > > problems? This should have been fixed SO long ago... a trailer on > > list messages should be a TRAILER under all circumstances. What > > gives? > > To do this would require parsing the HTML to determine the insertion > point. It could be done using any good text-manipulation language, > even VBScript. > > > is there ANY way to secure the email addresses of list members? > > This is a perplexing, seemingly untested allegation you're making. > You're not correct in saying that the LIST command is irrevocably > enabled, although the docs are misleading on this point, making it > seem like a loophole where there isn't one. > > -Sandy > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
