Full Disclosure mailing list archives
Re: Re: [Mailman-Developers] mailman email harvester
From: Valdis.Kletnieks () vt edu
Date: Fri, 11 Feb 2005 22:34:26 -0500
On Sat, 12 Feb 2005 02:48:56 +0100, Bernhard Kuemel said:
If hashcash (http://www.hashcash.org/) gets integrated in our mail systems we no longer need to hide or obfuscate our email addresses.
On the other hand, widespread distribution of hashcash will probably mean the end of many mailing lists, because you can't trust users to actually whitelist everything they subscribe to. And remember that the whole *idea* of hashcash is that you make it impractical for somebody to send 3,000 pieces of mail. I'm sure netsys.com wouldn't want to keep full-disclosure if they had to do hashcash for even 10% of their users. I'll go out on a limb and predict that if hashcash catches on, most major mailing list packages will quickly acquire features to auto-unsub and auto-blacklist all addresses from domains that present a hashcash challenge, just out of self-defense. (And yes, unsub and blacklist *the entire domain* - if foo.com is bouncing mail that hasn't been whitelisted, you have to ban foo.com from all your lists. Otherwise you can be DoS'ed (either intentionally or accidentally) by simply subscribing 15 or 20 addresses and "forgetting" to whitelist the mailing list... I'll overlook the issues caused when you *dont know* what to whitelist. For instance - many mailing lists (including this one) have a "confirmation of subscription" check. For bonus points - should you have whitelisted: a) full-disclosure () lists netsys com (the actual list name) b) full-disclosure-request () lists netsys com (the rfc822 header on my confirm) c) full-disclosure-admin () lists netsys com (the rfc821 MAIL FROM:) d) mailman@ e) majordomo@ f) listserv@ (One or more answers may or may not be correct. Remember that at the time you send your subscription request, you probably have not actually seen any mail from the site, so you can't say "whitelist the address this mail came from"...) There's also all the stuff that things like amazon, ebay, your bank, your insurance company, your utility companies, etc... all send out, that users will forget to whitelist. But yeah, other than all those minor details, hashcash is a fine solution. ;)
Attachment:
_bin
Description:
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Re: [Mailman-Developers] mailman email harvester Bernhard Kuemel (Feb 11)
- Re: Re: [Mailman-Developers] mailman email harvester Valdis . Kletnieks (Feb 11)
- mailman email harvester Bernhard Kuemel (Feb 12)
- Re: mailman email harvester Valdis . Kletnieks (Feb 12)
- mailman email harvester Bernhard Kuemel (Feb 12)
- Re: Re: [Mailman-Developers] mailman email harvester Valdis . Kletnieks (Feb 11)
- RE: Re: [Mailman-Developers] mailman emailharvester Aditya Deshmukh (Feb 13)
- Re: Re: [Mailman-Developers] mailman emailharvester Volker Tanger (Feb 13)
- RE: Re: [Mailman-Developers] mailman emailharvester Aditya Deshmukh (Feb 15)
- RE: Re: [Mailman-Developers] mailman emailharvester Aditya Deshmukh (Feb 13)
- Re: Re: [Mailman-Developers] mailman email harvester Valdis . Kletnieks (Feb 11)