Great Circle Associates Majordomo-Users
(January 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: "trusted users" for commands needing &pproval?
From: Jason L Tibbitts III <tibbs @ hpc . uh . edu>
Date: 03 Jan 1997 11:43:02 -0600
To: "Kendall P Bullen" <kendall @ his . com>
Cc: majordomo-users @ GreatCircle . COM (MajorDomo Users)
In-reply-to: "Kendall P Bullen"'s message of Fri, 3 Jan 1997 12:20:21 -0500
References: Jim Reisert's message of Fri, 03 Jan 1997 10:24:47 -0500 <9701031524.AA21677@sttng.databook.com> <v03007808aef2efe3a395@[205.252.121.166]>

>>>>> "KPB" == Kendall P Bullen <kendall@his.com> writes:

KPB> Then why is there a restrict_post feature?

To cut down on spam.  I don't see why you have to ask this.  On one hand we
have complete access over the lists, which we password protect.  On the
other hand we have simple posting to the list.  They let tour groups into
NORAD, but they still put a big lock on the door to the room with the big
red button.

Your question suggests that the dichotomy is useless; that we should have
either free access to all list commands and posting rights, or that we
should have password access to all message commands and require a password
to post to the list.  That's obviously not a great solution, although the
existence of PGP and the like does offer new options (which we don't yet
take into consideration, but who knows what the future holds).

KPB> Since you'd have to know who is a "trusted" user for administrativa,
KPB> and presumably it would be non-obvious (if you're smart), unless
KPB> someone tried it from every e-mail address they saw on a list, it
KPB> doesn't seem like a big danger to me.

So you mean to say it's "difficult" to figure out who the list owner is?
Perhaps by sending mail to them (via owner-list), or seeing what an SMTP
EXPN on owner-list points to?  Heck, just hanging around on a list for a
little while usually reveals who the owner is, though not always.  You're
arguing security through obscurity.

KPB> (And I presume that the attempts that failed would bounce to the list
KPB> owner, so they would know someone was trying to hack the list.)

And what would their recourse be?  Remove themselves from the trusted list?
Alert some postmaster and hope they stop?  There's no password to change,
remember?

 - J<


Follow-Ups:
References:
Indexed By Date Previous: Re: Error setting up Major Domo
From: Dave Wolfe <dwolfe@risc.sps.mot.com>
Next: Fixed: Error setting up Major Domo
From: "Nels Lindquist" <nels@maei.ca>
Indexed By Thread Previous: Re: "trusted users" for commands needing &pproval?
From: "Kendall P Bullen" <kendall@his.com>
Next: Re: "trusted users" for commands needing &pproval?
From: richard welty <welty@balltown.cma.com>

Google
 
Search Internet Search www.greatcircle.com