[Mailman-Users] Large lists and Postfix
Dave Sill
de5 at sws5.ctd.ornl.gov
Wed Mar 17 16:45:53 CET 1999
Christopher Lindsey <lindsey at ncsa.uiuc.edu> wrote:
>
>Regarding Dave's comments about confirmations... majordomo 1.94.4 (don't
>know about the almost-alpha 2.0) has an easily spoofable confirmation
>key.
Oh? How so? Don't you have to know the $cookie_seed? Or are you
assuming everyone uses the default? I've never had a problem with
faked confirmations.
>Regarding Dave's comments about "The major remaining problem area is
>people who can't remember their subscription address and therefore
>can't unsubscribe..." Look at the Received: headers. :) Seriously, there's
>no other user-specific key added to the messages.
Actually, qmail's VERP helps a lot here--if the user's MTA or MDA puts
the envelope return path in a header field. There are users on systems
that strip some useful headers and fail to include useful
information. I pity them, but it's really not my problem.
-Dave
More information about the Mailman-Users
mailing list