List Archive: gentoo-project
Lately we've been seeing a LOT of spam being sent to the mailing list
subscribe mechanism, with the side effect that the subscribe mechanism
responds to the From header address with a confirmation request. That
address (along with the envelope sender) are unfortunately forged.
The volume of the confirmation requests is getting worse than direct
spams, because the spam filtering considers the confirmation requests to
be valid email (they would be, except for the fact they are
unsolicited).
To combat this problem, I'd like us to consider switching the subscribe
mechanism for the mailing lists to be a web form (protected with
recaptcha). Unsubscribe will continue to be offered as an email action
for the moment, because it ignores the mail if the address was not
subscribed.
--
Robin Hugh Johnson
Gentoo Linux Developer & Infra Guy
E-Mail : robbat2@g.o
GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85
|
|