On 09/25/2017 01:49 PM, Wes Turner wrote:
> These passwords should not be recoverable; because they should be only
> stored as a one-way salted hash with n rounds.


This is a very well known issue with Mailman 2.1 and prior versions. See
<https://bugs.launchpad.net/mailman/+bug/265179>.

...
> Is this fixed in Mailman3?


Yes.

-- 
Mark Sapiro <[email protected]>        The highway is for gamblers,
San Francisco Bay Area, California    better use your sense - B. Dylan
_______________________________________________
Security-SIG mailing list
[email protected]
https://mail.python.org/mailman/listinfo/security-sig

Reply via email to