[svn.haxx.se] · SVN Dev · SVN Users · SVN Org · TSVN Dev · TSVN Users · Subclipse Dev · Subclipse Users · this month's index

Re: [TSVN] Slow

From: Molle Bestefich <molle.bestefich_at_gmail.com>
Date: 2005-05-30 11:20:48 CEST

Lübbe Onken wrote:
> Jochen,
> Your automatic e-mail slave wrote:
> > Return Receipt
> > Your document
> > RE: [TSVN] Slow
> > was received by:
> > Jochen Klemm/408/DCAG/DCX
> > at:
> > 30/05/2005 08:49:37
> >
>
> Can you please turn off return receipts and vacation scripts for this
> mailing list.

Uhm, actually, I'd say that we're at fault.

Henning Larsen <h.larsen@risoe.dk> sent a mail with some fancy headers:
X-No-Archive: yes
Disposition-Notification-To: h.larsen@risoe.dk

Any mailing list with respect for itself should at least strip the
Disposition-Notification-To part.
Otherwise it will (potentially) disclose email adresses of every
member of the mailing list to h.larsen@risoe.dk (or anybody else that
are dumb enough to attach that header to a mail sent to a mailing list
or to everybody in general).

With "potentially", I mean that whether the above will happen depends
on your particular e-mail client and the preferences you've setup.
And I'll agree that Jochen's e-mail client is a bit odd - it should
ignore the Disposition-Notification-To when it doesn't match the
Return-Path header.

In any case, from a security point of view, we should definitely strip it.

---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@tortoisesvn.tigris.org
For additional commands, e-mail: dev-help@tortoisesvn.tigris.org
Received on Mon May 30 11:21:20 2005

This is an archived mail posted to the TortoiseSVN Dev mailing list.

This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.