Hacker News new | ask | show | jobs
by AncientPC 5069 days ago
It's fun to bash on the most recent security naiveté, but can someone explain why GNU Mailman still emails users' passwords after subscribing?

Mailman warns users that passwords will be mailed plaintext, but why mail passwords to begin with?

2 comments

For accounts that I use rarely and have a low cost even if compromised, I prefer convenience over security.

As mailman has a fairly technical audience and reminds users that passwords are stored/sent in plaintext, I see it as a feature, not a bug.

Because nobody has patched it. Go there, download the source, write a patch, submit it.