[mlpack] Why is my password plaintext?

Ryan Curtin ryan at ratml.org
Thu Aug 1 09:39:57 EDT 2019


On Thu, Aug 01, 2019 at 08:32:24AM -0500, Jack Harris wrote:
> Take me off this list, I unsubscribed like 10 times, and you just EMAILED my password! 

Hey Jack,

Yours is a common first-of-the-month message when reminders go out.

You can blame mailman (the list software) for the plaintext password,
not one of the mlpack developers personally.  That's how mailman has
done it since... forever.  Maybe they should update it, but honestly is
there any reason?  What can a malicious entity do with your mailman
password (which is generally randomly generated anyway)?  Unsubscribe
you from the list?  Put your subscription in digest mode?  Both of those
things sound like they would be improvements for you, and they seem
pretty far away from identity theft.

If you follow the link at the bottom of every email:

http://knife.lugatgt.org/cgi-bin/mailman/listinfo/mlpack

then you can see at the bottom of the page something that says "To
unsubscribe from mlpack, get a password reminder, ..., enter your
subscription email address".

You said you've done that "like 10 times", but there's no bug in
mailman to my knowledge.  My guess is that you tried to unsubscribe with
a different email than you subscribed with, or that you did not then
click the link in the unsubscription request email that you received
(and mailman told you that it sent you).

In any case, you're clearly frustrated, so I've just gone ahead and hit
the unsubscribe button an eleventh time for you.  You are now released
from your monthly password reminder email and occasional mlpack
discussion.  Enjoy your slightly-cleaner inbox. :)

Have a good one!

-- 
Ryan Curtin    | "I love it when a plan comes together."
ryan at ratml.org |   - Hannibal Smith


More information about the mlpack mailing list