George Mitchell, [GM] wrote: GM> Also, rational or not, the list will undoubtedly lose some GM> posters. Perhaps we will gain others through GMane, but my gut GM> tells me it will be a net loss.
Perhaps this may have happened if we had just informed the group, without prior discussion that the lists were mirrored. OTOH, we decided to take a different route. We first did our research and assessed GMane's security ourselves since we don't exactly enjoy being spammed; neither do we wish to have our membership end up being spammed on account of our actions. The 3 moderators here all agreed that GMane is secure enough for what we wish to do. We then made the list know a week ago that we were thinking about doing this. A long discussion ensued where all concerns were aired. No concern stood up to technical clarification and examination of the facts concerning GMane's security model. After a week, no one posted a convincing reason to hold GMane's security at reasonable fault, so we decided to go ahead. *Still*, we decided to tread cautiously by making an announcement 48 hours before implementation. The intention here was to make any last minute views/issues be heard and clarified. After all of this, I really doubt there'll be a net loss. I do think that some of the negative reaction is understandable. However, the persistence after examining the facts is interesting and IMO irrational, especially when considering the fact that our addresses are not currently fully secure. A spammer can easily subscribe to this list to get our addresses. It's either that you wish for your address to be absolutely secure or not. If you care so much about your address why use it on this list at all? GM> And, I'm not convinced people's fears are completely irrational. I actually think they are. Gmane is able to secure your addresses better than they are currently secured. Hence the irrationality behind the concern. After careful reading of how these security measures work, there's really nothing to have reasonable doubts about. GM> For example, it appears that GMane only encrypts the domain part GM> of the address. When viewing the news via the web interface, yes. Like Yahoogroups, it obfuscates the address, i.e., replacing the domain part of the address with dots. Many here are on Yahoo groups and have no problem with Yahoo's security where their addresses are concerned. As a result, if there's a concern when GMane uses the same system for their web interface, this perplexes me. GM> For my posts the domain is available from the Message-Id. So, all GM> the parts are there in the clear and some pretty trivial parsing GM> could reassemble it. For messages downloaded with a newsreader, all addresses in headers will be encrypted. This is different from simple obfuscation that you see via the web interface. This is all documented on www.gmane.org GM> Whether this would be worthwhile for a spammer to attempt is GM> certainly questionable, Indeed!! Don't you think it would be easier to just subscribe to this list for a while and then harvest the addresses. Spammers don't seem to find that simple exercise worth their while. GM> but it raises enough doubt in my mind about security to give me GM> pause. Well, of course. No one is saying it shouldn't. It raised my concerns as well. After investigating, I'm no longer concerned. GM> I don't have the time or inclination to carefully consider the GM> implications of their security model. Who knows what I'm missing? True. It's up to you to decide what you wish to do. -- -= Allie Martin =- | List Moderator PGPKeys: http://key.ac-martin.com ____________________________________ Using TB! v2.04.7 on WinXP Pro (SP1)
pgp00000.pgp
Description: PGP signature
________________________________________________ Current version is 2.04.7 | 'Using TBUDL' information: http://www.silverstones.com/thebat/TBUDLInfo.html

