https://bugzilla.wikimedia.org/show_bug.cgi?id=48786
--- Comment #20 from Krinkle <[email protected]> --- (In reply to Marc A. Pelletier from comment #19) > @Krinkle: Nothing; email is not secure and there is no sender verification. > Anyone can fake From: headers. > > > I'm pretty sure something somewhere already ensures that you can't just > > imitate someone @wikimedia.org from outside production (e.g. my home > > computer) and successfully post to a members-only list like > > mediawiki-announce. > > Only insofar, apparently, as it doesn't come from outside our network. > > (I've tested it and, at the very least, naive rewriting of the From: header > is filtered). But we bypass that filtering when the mail is sent from labs to production? -- You are receiving this mail because: You are on the CC list for the bug. _______________________________________________ Wikibugs-l mailing list [email protected] https://lists.wikimedia.org/mailman/listinfo/wikibugs-l
