Password in mailing list memberships reminder

MLeo mleodaalder at gmail.com
Wed Dec 1 08:10:56 PST 2010


Loads of mailing list software have this (this particular software packet is
used by a lot of other software projects, such as the Haskell mailing
lists). In fact, when you signed up it warned you about this, and offered a
randomly generated one.

On Wed, Dec 1, 2010 at 16:02, David Stibbe <dstibbe at gmail.com> wrote:

> I just got a mailinglist reminder, which is a very kind service.
> However, at the bottom of the message I found this:
>
> > ....
> > If you have questions, problems, comments, etc, send them to
> > mailman-owner at openjdk.java.net.  Thanks!
> >
> > Passwords for dstibbe at gmail.com:
> >
> > List                                     Password // URL
> > ----                                     --------
> > lambda-dev at openjdk.java.net              ******
> >
> http://mail.openjdk.java.net/mailman/options/lambda-dev/dstibbe%40gmail.com
> >
>
> ( Password was *-ed by me.)
>
> Why on earth is de mailinglist sending me my password in PLAINTEXT in
> a REMINDER?
> Why does it even know what my plaintext password is?
>
> When is openjdk planning to fix this amateuristic setup?
>
>
> Kind regards,
> David
>
>


More information about the lambda-dev mailing list