Skip to Content.
Sympa Menu

en - [sympa-users] Question re users not subscribed to any lists

Subject: The mailing list for listmasters using Sympa

List archive

Chronological Thread  
  • From: "Ward, Michael" <address@concealed>
  • To: sympa-users <address@concealed>
  • Subject: [sympa-users] Question re users not subscribed to any lists
  • Date: Thu, 10 Jan 2008 09:34:29 +1300

Hi,

 

The concern has been raised here about the fact that anyone (as our sympa site is exposed to the internet) is able to create accounts, even though they won’t be able to join any lists as none are public. I’m not so concerned about this as there is little they can do (other than trying to hack the site!) with the account,  but I was wondering if accounts that are not members of any lists are automatically purged from Sympa after a set time? We have to allow anyone to create accounts as our lists aren’t restricted to just people within our organisation.

 

Also, to reduce the risk of bots automatically creating accounts, can Sympa be set up with a confirmation system? Something along the lines of: user creates account via the Sympa website, an email is sent to the user with a link in the email that the user is required to click before the account is activated.

 

The answer to this is probably in the doco... but I’m also interested in peoples comments re the security risks, and it doesn’t hurt for everyone to hear the answer!

Regards,
Michael

 




Archive powered by MHonArc 2.6.19+.

Top of Page