> If this is a vulnerability in IMAILSRV, it is one in 99% of lists, > public or private, on the Internet. I understand that you did not have > list serving experience before you purchased IMail, and it could be > explained much better in the documentation (though the trial version > provides ample evidence of this limitation). In sum, though, this is > not a grevious oversight on Ipswitch's part, nor would implementing > this feature be the first order of business in improving IMAILSRV.
Indeed, it is the documentation that has led me astray in almost all of the issues I have presented. At this point, it would be nice if in future releases, iMail could conceal member email addresses in all potential discovery areas. > This applies to the global trailer.txt, not to list trailers, as I > said in my reply. You were reading the wrong part of the manual, and > did not test. I will go back and attempt to better understand this. > List management is not a real cash cow, presumably...that's why Web > Messaging and Web Calendaring have been emphasized in development. I > agree that it would be good, but none of us have been holding our > breath, since this module hasn't changed appreciably (except for some > undocumented fixes) in four versions. It has become very clear to me that iMail as a list server is not really an important part of the server software as a whole. Thank you. > > > HTML/Rich Text messages are a fact of life, and more to the point > > are implemented features by MANY internet users, and server products > > should keep up with that. > > They should indeed. I appreciate your willingness to agree with me on this point. > > > 3. Being a good citizen has little to do with whether or > not one sends an > > email message in plain text or HTML. > > I'm speaking specifically of "Internet citizens," however outdated the > concept. I'm sure that there are many, say, evil CEOs (well, maybe not > that many) who use plain text. I understood completely what you were speaking of. As a "citizen" of this list, where it has been made clear to me that HTML messages are not appreciated, I would not be a "good citizen" if I continued to post in HTML anyway. However, members of OUR list are not asked to post in plain text only... because of the reasons I stated. So, across all "communities" of which one may be a "citizen", there should not be a blanket statement that users are not "good citizens" if they post in HTML. It's not a fair assessment. > It's fine for a listserv, just not fine for tagging with a trailer. If > I decide to send JPEG-only advertisements to my customers, IMAILSRV > won't blink, but how it's supposed to add trailers without advanced > MIME processing is beyond me. I guess that's what I was asking about... and this is an honest question -- would it be that hard for the iMail developers to implement? (I know -- I should ask them!) > > 4. My claim that list member's email addresses are NOT > private (in other > > words, any list member can discover the email addresses of > all other list > > members on a MODERATED, "PRIVATE" list) is not an > "allegation", it's a > > tested frickin' fact. > > As has now been shown to you, you didn't "frickin'" test your "fact" > with the correct laboratory setup, or you'd have known that USERS > cannot get this information, like I said: it seems like a loophole > from the docs, but it is not. I almost challenged you to get the > membership of the IMail Forum, but I thought that'd be too blatant. I very much tested my fact -- I just didn't adjust my "lab setup" to support a hidden discrepancy. Remember, I was also being guided by blatant text in the manual. As a "member" of a list, and supported by a paragraph IN the help system, I discovered a discrepancy that appeared to be a privacy concern. Once again, "disabled" should mean "disabled"... unless the "except when..." is spelled out CLEARLY. > Don't think you tested this. Once pushed in the right direction, you are correct, and I did finally test. I will accept partial blame for not going one step further and becoming a "list member ONLY", separate from the list owner. > > > the article I mentioned also demonstrates how list member email > > addresses can be discovered, just by reading the messages to the > > list using certain email clients. > > Like, say, ANY client? If I use outlook express, I can't see the sender's email address... unless I am missing something there, too... which I will once again admit. > > > What is so perplexing about wanting to keep list member's email > > addresses private, especially when they can be delivered in BULK to > > anyone who knows the LIST command? > > Everybody knows the LIST command is ripe for spammers--but, as has > been shown to you, it can be disabled. What's left is subscribing to a > list, gathering addresses over time, and selling them (or being) a > spamhouse. This method is used infrequently at best. It's not a worry > for the people on this list, most of whom are professional sysdmins, > nor for those on the most popular security mailing lists. Full > anonymity, for legal and practical reasons (forging is made infallible > if all headers, including source IP, are erased), is rarely used on > mailing lists, and IMAILSRV's lack of support of this is unsurprising. Yes, the LIST command can be disabled... I can see this now. I am not as much concerned about spammers as I am in wanting to keep the list member's email addresses private from other members whom I have manually subscribed. We wish to distribute information between list members, and allow them to hold conversations between each other on the list, without them knowing each other's addresses unless they specifically provide it to the list in a message. This would be to uphold their privacy. In all, is it going to be a HUGE deal? I suppose not, especially since I know that that LIST disabling feature really does work. Would it be nice for the server to be able to remove all trace of identity of the posting user before their message goes out to the list? Yeah, it really would. But I guess I won't "hold my breath" since the list server feature of iMail is not that important to IPSwitch or anyone else, in general. Sandy, I thank you for your candid replies. > > -Sandy > > > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html > List Archive: > http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ > Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/ > To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
