Re: Unsubscription even when not confirmed?

 
From: "Mariano Absatz" <el.baby@PROTECTED>
Date: September 6th 2006

Justin,

this is getting worse and worse now dada is unsusbcribing me every day I'm enclosing the 4 unsubscription messages I got complete with headers for you to watch

Other thing when I re-subscribe (via the web form), I get not one, but three identical messages I tried to subscribe from another address and the same thing happens

What I'm thinking is that the uniqness of the pin is probably too weak it is always the same for the same address (even the same for subscribe/unsubscribe) maybe it should have a clock-dependent salt?

Maybe someone has guessed (calculated?) the pin corresponding to my address?

Are you able to check that?

Now that I make a couple of tests (with another address) and take a peek at the source, I see that the whole subscribe/unsubscribe confirmation process is completely stateless I think this should be avoided it will obviously complicate the algorithm but the point is, now that someone knows my pin on the current configuration of http://mojo skazat com/cgi-bin/dada/mail cgi it is simply a matter of loading http://mojo skazat com/cgi-bin/dada/mail cgi/u/dadadev/el baby/gmail com// or http://mojo skazat com/cgi-bin/dada/mail cgi/n/dadadev/el baby/gmail com// (and manually doing the captcha thing) to unsubscribe me or subscribe me without I being involved in the transaction

-- Mariano Absatz - El Baby el (dot) baby (AT) gmail (dot) com el (punto) baby (ARROBA:@) gmail (punto) com

Dada Mail (Justin Simoni) escribió el 03/09/06 20:33: > >

On Sep 3, 2006, at 4:30 PM, Mariano Absatz wrote: >

wtf???

Yesterday again something (someone?) decided to unsubscribe me from the list I got a message confirming my unsubscription, and this time I didn't even started an unsubscription process Is something wrong with dada?

Hmm,

Not sure,

Does anybody want to try to crack the pin creation algorithm?

It's not the most comples scheme in the world - it's rather simple, but should generate a unique (ish) pin that's different for every install of Dada Mail But it may be easy enough to look at two example of pin number and the email addresses they're generated from and figure out what any email address's pin would be

--Justin Simoni

: Dada Mail "Write Once - Distribute Everywhere" Email Communication Software

url: http://mojo skazat com aolim: leaddadaist

On Sep 3, 2006, at 4:30 PM, Mariano Absatz wrote:

>

wtf???

Yesterday again something (someone?) decided to unsubscribe me from the list I got a message confirming my unsubscription, and this time I didn't even started an unsubscription process Is something wrong with dada?

On 2 Sep 2006 13:53:56 -0000, Mariano Absatz el.baby@PROTECTED wrote: >

Hi Justin,

yesterday I "started" a removal for myself from the list, only to answer properly to this message: http://mojo skazat com/cgi-bin/dada/mail cgi/archive/dadadev/20060830102506/

I received the confirmation e-mail and properly ignored it in order to stay subscribed

However, a few hours later, I received a message from the list confirming that I was effectively unsubscribed

Is this a feature or a bug?

That is are you using a script to "auto-confirm" unsubscriptions (so that people who can't understand 3-way confirmations es eventually unsubscribed)?

If that is so, the "unsubscription confirmation message" should also include a link for actively not confirming unsubscription otherwise, what states the unsubscription message is false

I don't think someone else would've clicked my unsubscribe confirmation, since, as you can see in http://mojo skazat com/cgi-bin/dada/mail cgi/archive/dadadev/20060901094002/

I didn't publish it

  • This mailing list is a public mailing list - anyone may join or leave, at any time.
  • This mailing list is a group discussion list (unmoderated)
  • Start a new thread, email: dadadev@dadamailproject.com

This is the developer discussion mailing list for Dada Mail.

If you are just looking for support Dada Mail, consult the message boards at:

https://forum.dadamailproject.com

Documentation for Dada Mail:

https://dadamailproject.com/d

Specifically, see the Error FAQ:

https://dadamailproject.com/d/FAQ-errors.pod.html

To post to this list, send a message to:

mailto:dadadev@dadamailproject.com

All subscribers of this list may post to the list itself.

Topics that are welcome:

  • Constructive critiques on the program (I like, "x", but, "y" needs some work - here's an idea on how to make this better...)
  • Bug/Error reports
  • Bug fixes
  • Request For Comments on any changes to the program
  • Help customizing Dada Mail for your own needs
  • Patches
  • Language Translations
  • Support Documentation/Doc editing, FAQ's, etc.
  • Discussion of any changes that you would like to be committed to the next version of Dada Mail -

Dada Mail is on Github:

https://github.com/justingit/dada-mail/

If you would like to fork, branch, send over PRs, open up issues, etc.

Privacy Policy:

This Privacy Policy is for this mailing list, and this mailing list only.

Email addresses collection through this mailing list are used explicitly to work within this email discussion list.

We only collect email addresses through our Closed-Loop Opt-In system.

We don't use your email address for any other purpose.

We won't be sharing your email address with any other entity.

Unsubscription can be done at any time. Please contact us at: justin@dadamailproject.com for any help regarding your subscription, including removal from the mailing list.

All mailing list messages sent from us will include a subscription removal link, which will allow you to remove yourself from this mailing list automatically, and permanently.

All consent to use your email address for any other purpose stated at the time of the mailing list subscription will also be revoked upon mailing list removal.