Re: [Mailman-Developers] Remediation for fake member creation

2016-08-24 Thread Stephen J. Turnbull
Franck Martin writes: > Can't you send the email subscription request to moderation before > the email confirmation is sent? The option "subscription needs approval" is available, and I use it for my student lists, etc. They're closed lists initially populated with "mass subscribe", but student

Re: [Mailman-Developers] Remediation for fake member creation

2016-08-23 Thread Franck Martin
- Original Message - > From: "Stephen J. Turnbull" > To: "Franck Martin" > Cc: "Barry Warsaw" , "mailman-developers" > > Sent: Monday, August 22, 2016 9:06:31 PM > Subject: Re: [Mailman-Developers] Remediation for fake member

Re: [Mailman-Developers] Remediation for fake member creation

2016-08-22 Thread Stephen J. Turnbull
Franck Martin writes: > May be a captcha? Or some more modern techniques... Captchas aren't applicable to email requests. It will be harder than that. We could turn off subscription by email after user creation so that users would get only one email per email at most. From Mailman's point of

Re: [Mailman-Developers] Remediation for fake member creation

2016-08-22 Thread Franck Martin
- Original Message - > From: "Barry Warsaw" > To: "mailman-developers" > Sent: Monday, August 22, 2016 2:43:06 PM > Subject: Re: [Mailman-Developers] Remediation for fake member creation > On Aug 22, 2016, at 01:03 PM, Franck Martin wrote: > &

Re: [Mailman-Developers] Remediation for fake member creation

2016-08-22 Thread Barry Warsaw
On Aug 22, 2016, at 01:03 PM, Franck Martin wrote: >While mailman does double opt-in, one can still fill a mailbox with account >confirmations, what are the methods to stop a bot submitting email addresses >for registration across several lists? Mailman 3 will not pend a registration request more

[Mailman-Developers] Remediation for fake member creation

2016-08-22 Thread Franck Martin
I'm not sure if you have seen the following blog posts: https://wordtothewise.com/2016/08/subscription-bombing-esps-spamhaus/ https://wordtothewise.com/2016/08/spamhaus-comments-on-subscription-attack/ https://wordtothewise.com/2016/08/ongoing-subscription-attack/ While mailman does double op