[Mailman-Developers] Mailman 2.1.23 patch for MIME changes with headers or footers

2017-03-15 Thread Fothergill, Iain
Hi, I hope this hits the right people (looking at some archives it seems to be, despite the list being mainly for MM3). Apologies if you consider it just noise. I have a patch for Mailman 2.1.23 for MIME munging when there are no headers or footers. There is code to prevent this from happen

Re: [Mailman-Developers] Encrypted lists predictable difficulties and implementation needs

2017-03-15 Thread Rich Kulawiec
All of these proposals overlook significant known, current threats -- none of which they're capable of addressing, but some of which badly undercut the suggested approaches. To list just one of those -- albeit a rather prominent one -- the Internet's population of hijacked systems (aka bots or zo

Re: [Mailman-Developers] Mailman 2.1.23 patch for MIME changes with headers or footers

2017-03-15 Thread Mark Sapiro
On 03/15/2017 09:37 AM, Fothergill, Iain wrote: > > I hope this hits the right people (looking at some archives it seems to be, > despite the list being mainly for MM3). Apologies if you consider it just > noise. I'm here. It probably would have been better to report this at

Re: [Mailman-Developers] Encrypted lists predictable difficulties and implementation needs

2017-03-15 Thread J.B. Nicholson
Rich Kulawiec wrote: What all of this means is that once a list passes N members, where we can debate about N, the probability that at least one of those members has already been compromised even before they've joined the list starts rapidly increasing. I understand there are more insecure devi