Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Mailing list settings #543

Open
christi-stripe opened this issue Feb 26, 2024 · 0 comments
Open

Mailing list settings #543

christi-stripe opened this issue Feb 26, 2024 · 0 comments

Comments

@christi-stripe
Copy link

The mailing list linked from the README (https://groups.google.com/g/faye-users) has hundreds of spam messages sent to it and exposes users' email addresses. I'd like to join this mailing list to stay up to date on security issues, but don't want to sign up for spam or expose my address.

The current privacy configuration is as follows:
Screenshot 2024-02-26 at 12 56 48 PM

I believe that more secure settings that would prevent the above issues are as follows:
Screenshot 2024-02-26 at 1 00 05 PM

Along with this, the group owner needs to ban the current spammers.

Allowing group members to view members means that the full member list will be exposed to anyone who is able to join the group. Currently anyone may join, but even after that is restricted, this is still undesirable as this means that if there were some zero day vulnerability, a malicious user would only need to gain access to this mailing list to get a list of potential attack targets.

Allowing non-members to view conversations means that the email address of posters will be exposed publicly.

Allowing anyone on the web to join the group means that spammers can join and immediately post.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant