[cryptome] Re: [Cryptography] Why is emailing me my password?

  • From: Kelvin Quee (魏有豪) <kelvin@xxxxxxxx>
  • To: cryptome@xxxxxxxxxxxxx
  • Date: Wed, 2 Oct 2013 12:04:58 +0800

Greg, it is stated quite clearly that you should be using a
not-so-important password -

"""You may enter a privacy password below. This provides only mild
security, but should prevent others from messing with your subscription. Do
not use a valuable password as it will occasionally be emailed back to you
in cleartext."""

http://www.metzdowd.com/mailman/listinfo/cryptography

If you Google that paragraph, you will see that this is common practice
among most Mailman installations.

In short, you should not be using an important password for your mailing
lists, Cryptography or otherwise.



Kelvin Quee (魏有豪)
+65 9177 3635

gpg: AB3DB8AC


On Tue, Oct 1, 2013 at 11:02 PM, John Young <jya@xxxxxxxxxxxx> wrote:

> The several crypto lists run by mailman email passwords monthly.
> Open crypto lists are not meant to be more trustworthy than open
> crypto.
>
>
>
> At 10:28 AM 10/1/2013, you wrote:
>
>> This falls somewhere in the land of beyond-the-absurd.
>>
>> Just got this message from your robot:
>>
>> On Oct 1, 2013, at 5:00 AM, mailman-owner@xxxxxxxxxxxx wrote:
>>
>> > If you have questions, problems, comments, etc, send them to
>> > mailman-owner@xxxxxxxxxxxx.  Thanks!
>> >
>> > Passwords for greg@xxxxxxxxxxxxxxx:
>> >
>> > List                                     Password // URL
>> > ----                                     --------
>> > cryptography@xxxxxxxxxxxx                iPoopInYourHat
>> > http://www.metzdowd.com/**mailman/options/cryptography/**
>> greg%40kinostudios.com<http://www.metzdowd.com/mailman/options/cryptography/greg%40kinostudios.com>
>>
>> So, my password, iPoopInYourHat, is being sent to me in the clear by your
>> servers.
>>
>> Of all the places on the internet, this would be on the last places I
>> would expect this to happen.
>>
>> - Greg
>>
>> --
>> Please do not email me anything that you are not comfortable also sharing
>> with the NSA.
>>
>>
>>
>> ______________________________**_________________
>> The cryptography mailing list
>> cryptography@xxxxxxxxxxxx
>> http://www.metzdowd.com/**mailman/listinfo/cryptography<http://www.metzdowd.com/mailman/listinfo/cryptography>
>>
>
>
>
>

Other related posts: