On Wed, Aug 26, 2020 at 09:28:30AM -0400, Jim Popovitch via Mailman-Users wrote:
> So, I have volunteered to spearhead an effort to add one or two more
> people to the Mailman Coders group[2] in order to vet and approve new
> features that continue the long tradition of providing value to Mailman
> 2.x.  Who's with me on this?

1. Sure.

2. I'm finishing the book on it anyway, so I might as well. ;)

3. Captchas are a worst practice in security and should never be used.
They can be and are defeated at will by any adversary who wants to
trouble themselves to do so.  They're also user-hostile.  There are much
better methods available for protecting Mailman instances from abusers.

Yes yes I know I just signed myself up to explain those.  This is not
my first time. ;)

4. One of things that I discovered while doing (2) is that Mailman v2.x
expects that it has *outbound* HTTP access.  I need to write this up
so that the problem is understandable/arguable/fixable, but: it's a
really bad idea to presume that's the case, and it's an equally bad
idea to make it the case.

---rsk
------------------------------------------------------
Mailman-Users mailing list -- mailman-users@python.org
To unsubscribe send an email to mailman-users-le...@python.org
https://mail.python.org/mailman3/lists/mailman-users.python.org/
Mailman FAQ: http://wiki.list.org/x/AgA3
Security Policy: http://wiki.list.org/x/QIA9
Searchable Archives: https://www.mail-archive.com/mailman-users@python.org/
    https://mail.python.org/archives/list/mailman-users@python.org/

Reply via email to