George Mitchell, [GM] wrote:

GM> Also, rational or not, the list will undoubtedly lose some
GM> posters. Perhaps we will gain others through GMane, but my gut
GM> tells me it will be a net loss.

Perhaps this may have happened if we had just informed the group,
without prior discussion that the lists were mirrored.

OTOH, we decided to take a different route.

We first did our research and assessed GMane's security ourselves
since we don't exactly enjoy being spammed; neither do we wish to have
our membership end up being spammed on account of our actions. The 3
moderators here all agreed that GMane is secure enough for what we
wish to do.

We then made the list know a week ago that we were thinking about
doing this. A long discussion ensued where all concerns were aired.
No concern stood up to technical clarification and examination of the
facts concerning GMane's security model.

After a week, no one posted a convincing reason to hold GMane's
security at reasonable fault, so we decided to go ahead.

*Still*, we decided to tread cautiously by making an announcement 48
hours before implementation. The intention here was to make any last
minute views/issues be heard and clarified.

After all of this, I really doubt there'll be a net loss.

I do think that some of the negative reaction is understandable.
However, the persistence after examining the facts is interesting and
IMO irrational, especially when considering the fact that our
addresses are not currently fully secure. A spammer can easily
subscribe to this list to get our addresses. It's either that you wish
for your address to be absolutely secure or not. If you care so much
about your address why use it on this list at all?

GM> And, I'm not convinced people's fears are completely irrational.

I actually think they are. Gmane is able to secure your addresses
better than they are currently secured. Hence the irrationality behind
the concern.

After careful reading of how these security measures work, there's
really nothing to have reasonable doubts about.

GM> For example, it appears that GMane only encrypts the domain part
GM> of the address.

When viewing the news via the web interface, yes. Like Yahoogroups, it
obfuscates the address, i.e., replacing the domain part of the address
with dots.

Many here are on Yahoo groups and have no problem with Yahoo's
security where their addresses are concerned. As a result, if there's
a concern when GMane uses the same system for their web interface,
this perplexes me.

GM> For my posts the domain is available from the Message-Id. So, all
GM> the parts are there in the clear and some pretty trivial parsing
GM> could reassemble it.

For messages downloaded with a newsreader, all addresses in headers
will be encrypted. This is different from simple obfuscation that you
see via the web interface. This is all documented on www.gmane.org

GM> Whether this would be worthwhile for a spammer to attempt is
GM> certainly questionable,

Indeed!!

Don't you think it would be easier to just subscribe to this list for
a while and then harvest the addresses. Spammers don't seem to find
that simple exercise worth their while.

GM> but it raises enough doubt in my mind about security to give me
GM> pause.

Well, of course. No one is saying it shouldn't. It raised my concerns
as well. After investigating, I'm no longer concerned.

GM> I don't have the time or inclination to carefully consider the
GM> implications of their security model. Who knows what I'm missing?

True. It's up to you to decide what you wish to do.

-- 
-= Allie Martin =- | List Moderator
 PGPKeys: http://key.ac-martin.com
____________________________________
Using TB! v2.04.7 on WinXP Pro (SP1) 

Attachment: pgp00000.pgp
Description: PGP signature

________________________________________________
Current version is 2.04.7 | 'Using TBUDL' information:
http://www.silverstones.com/thebat/TBUDLInfo.html

Reply via email to