Confirming Membership of List

Gareth Ellis gareth at gsellis.com
Tue Jul 1 06:18:06 PDT 2014


It's a "feature" of mailman, and as far as I'm aware it's a random
password that only lets you unsubscribe.

The mailing list content is public anyway :
http://lists.infradead.org/pipermail/get_iplayer/

On Tue, Jul 1, 2014 at 2:02 PM, Chris J Brady <chrisjbrady at yahoo.com> wrote:
> In a master stroke of security - or rather in an appalling LACK of security - the mailing list owners / moderators have just sent me an email confirming my membership - which included MY PASSWORD IN PLAIN TEXT.
>
> For such a mailing list of potentially legally sensitive subject matter - i.e. how to hack the BBC's servers - this is an unacceptable breach of security.
>
> CJB.
>
> _______________________________________________
> get_iplayer mailing list
> get_iplayer at lists.infradead.org
> http://lists.infradead.org/mailman/listinfo/get_iplayer



More information about the get_iplayer mailing list