Re: [Gimp-user] password

2016-04-11 Thread Sam Ashley
Just a brief note to say that I'm so impressed with gimp!! It's
astonishingly good! I have been using a ppa (I use ubuntu studio 14.4
atm) for the cutting edge version of gimp for maybe a year or so (not
sure how long) and except for one small issue long ago it seems
impossible that it's the testing version. It never crashes and works so
well. It's a wonderful program.




On Sun, Apr 10, 2016, at 22:07, Joao S. O. Bueno wrote:
> Hi Sam -
> we apologize for your security deception there - but please note we
> just use out-of-the box mailing list software,
> lacking volunteer efforts to customize or modernize such software -
> the "mailman"  e-mail list software has been used as "finished
> software" and did not have significant uptdates
> in well over 10 years - it probably could see some help as well.
> 
> But, despite seeing you have a legitimate concern, the default Mailman
> message on the subscription site _does_ warn about the password being
> sent in cleatext afterwards:
>  "You may enter a privacy password below. This provides only mild
> security, but should prevent others from messing with your
> subscription. Do not use a valuable password as it will occasionally
> be emailed back to you in cleartext."
> (https://mail.gnome.org/mailman/listinfo/gimp-user-list)
> 
> So, our apologies again, I for one can understand that in these days
> of increase security and privacy awareness, as compared to mailman's
> age, one should expect the password not to be stored in a retrievable
> way in the servers. And as someone in the field, again, I for one,
> know very well that one should not expect people to read all the text
> surrounding the forms. (really: not your fault - it is just not
> feasible to read all the fine-print in all sites we do visit).
> 
> 
> Please, accept our apologies - I think I can say that for the GIMP
> team. If you have the resources and will to volunteer and improve
> that, or know someone who could, you are invited to step up and help.
> 
> (otherwise, just do change your password for a non-valuable one - the
> current state for the lists is that the password is kept in cleartext
> in the server. Also, there is no "password history" - so the sooner
> you change, the better).
> 
> Regards,
> 
>js (joão)
>   -><-
> 
> 
> On 10 April 2016 at 10:03, Sam Ashley  wrote:
> > New to this fabulous list and glad to be here, hi.
> >
> > Look I love gimp and am happy to join this list but please, if you
> > insist on sending passwords back to people in the clear at least say
> > that clearly in the sign up page right next to the password entry field.
> > Better yet, don't send it imho.
> >
> > --
> > http://www.fastmail.com - Access your email from home and the web
> >
> > ___
> > gimp-user-list mailing list
> > List address:gimp-user-list@gnome.org
> > List membership: https://mail.gnome.org/mailman/listinfo/gimp-user-list
> > List archives:   https://mail.gnome.org/archives/gimp-user-list

-- 
http://www.fastmail.com - The way an email service should be

___
gimp-user-list mailing list
List address:gimp-user-list@gnome.org
List membership: https://mail.gnome.org/mailman/listinfo/gimp-user-list
List archives:   https://mail.gnome.org/archives/gimp-user-list

Re: [Gimp-user] password

2016-04-11 Thread Sam Ashley
Hi,

Oh no really I'm embarrassed. I over-reacted! And also it's my fault if
it says that and I didn't even read it!!

Well, sorry for that over concern. I guess I was just surprised. Many
thanks for your reply and sorry to have been too grumpy about it.

Sam

On Sun, Apr 10, 2016, at 22:07, Joao S. O. Bueno wrote:
> Hi Sam -
> we apologize for your security deception there - but please note we
> just use out-of-the box mailing list software,
> lacking volunteer efforts to customize or modernize such software -
> the "mailman"  e-mail list software has been used as "finished
> software" and did not have significant uptdates
> in well over 10 years - it probably could see some help as well.
> 
> But, despite seeing you have a legitimate concern, the default Mailman
> message on the subscription site _does_ warn about the password being
> sent in cleatext afterwards:
>  "You may enter a privacy password below. This provides only mild
> security, but should prevent others from messing with your
> subscription. Do not use a valuable password as it will occasionally
> be emailed back to you in cleartext."
> (https://mail.gnome.org/mailman/listinfo/gimp-user-list)
> 
> So, our apologies again, I for one can understand that in these days
> of increase security and privacy awareness, as compared to mailman's
> age, one should expect the password not to be stored in a retrievable
> way in the servers. And as someone in the field, again, I for one,
> know very well that one should not expect people to read all the text
> surrounding the forms. (really: not your fault - it is just not
> feasible to read all the fine-print in all sites we do visit).
> 
> 
> Please, accept our apologies - I think I can say that for the GIMP
> team. If you have the resources and will to volunteer and improve
> that, or know someone who could, you are invited to step up and help.
> 
> (otherwise, just do change your password for a non-valuable one - the
> current state for the lists is that the password is kept in cleartext
> in the server. Also, there is no "password history" - so the sooner
> you change, the better).
> 
> Regards,
> 
>js (joão)
>   -><-
> 
> 
> On 10 April 2016 at 10:03, Sam Ashley  wrote:
> > New to this fabulous list and glad to be here, hi.
> >
> > Look I love gimp and am happy to join this list but please, if you
> > insist on sending passwords back to people in the clear at least say
> > that clearly in the sign up page right next to the password entry field.
> > Better yet, don't send it imho.
> >
> > --
> > http://www.fastmail.com - Access your email from home and the web
> >
> > ___
> > gimp-user-list mailing list
> > List address:gimp-user-list@gnome.org
> > List membership: https://mail.gnome.org/mailman/listinfo/gimp-user-list
> > List archives:   https://mail.gnome.org/archives/gimp-user-list

-- 
http://www.fastmail.com - Does exactly what it says on the tin

___
gimp-user-list mailing list
List address:gimp-user-list@gnome.org
List membership: https://mail.gnome.org/mailman/listinfo/gimp-user-list
List archives:   https://mail.gnome.org/archives/gimp-user-list

Re: [Gimp-user] password

2016-04-10 Thread Joao S. O. Bueno
Hi Sam -
we apologize for your security deception there - but please note we
just use out-of-the box mailing list software,
lacking volunteer efforts to customize or modernize such software -
the "mailman"  e-mail list software has been used as "finished
software" and did not have significant uptdates
in well over 10 years - it probably could see some help as well.

But, despite seeing you have a legitimate concern, the default Mailman
message on the subscription site _does_ warn about the password being
sent in cleatext afterwards:
 "You may enter a privacy password below. This provides only mild
security, but should prevent others from messing with your
subscription. Do not use a valuable password as it will occasionally
be emailed back to you in cleartext."
(https://mail.gnome.org/mailman/listinfo/gimp-user-list)

So, our apologies again, I for one can understand that in these days
of increase security and privacy awareness, as compared to mailman's
age, one should expect the password not to be stored in a retrievable
way in the servers. And as someone in the field, again, I for one,
know very well that one should not expect people to read all the text
surrounding the forms. (really: not your fault - it is just not
feasible to read all the fine-print in all sites we do visit).


Please, accept our apologies - I think I can say that for the GIMP
team. If you have the resources and will to volunteer and improve
that, or know someone who could, you are invited to step up and help.

(otherwise, just do change your password for a non-valuable one - the
current state for the lists is that the password is kept in cleartext
in the server. Also, there is no "password history" - so the sooner
you change, the better).

Regards,

   js (joão)
  -><-


On 10 April 2016 at 10:03, Sam Ashley  wrote:
> New to this fabulous list and glad to be here, hi.
>
> Look I love gimp and am happy to join this list but please, if you
> insist on sending passwords back to people in the clear at least say
> that clearly in the sign up page right next to the password entry field.
> Better yet, don't send it imho.
>
> --
> http://www.fastmail.com - Access your email from home and the web
>
> ___
> gimp-user-list mailing list
> List address:gimp-user-list@gnome.org
> List membership: https://mail.gnome.org/mailman/listinfo/gimp-user-list
> List archives:   https://mail.gnome.org/archives/gimp-user-list
___
gimp-user-list mailing list
List address:gimp-user-list@gnome.org
List membership: https://mail.gnome.org/mailman/listinfo/gimp-user-list
List archives:   https://mail.gnome.org/archives/gimp-user-list