Comment 2 for bug 405277

Revision history for this message
Curtis Hovey (sinzui) wrote : Re: Allow private teams to join other teams

We now know enough information to address this as a part of the Managing Disclosure feature.
Arguments about team visibility and membership were missing the crucial point. The underlying issue is really that open teams cannot be trusted in some directions. We will change the restrictions from visibility to membership policy (bug 662844).

TeamParticipation leaks information. We need to secure it or at least identify all the ways it is unsecure.
Mailing lists and contact-this-tea can also leak information. We might decide that this is not a bug, but a policy decision; no team is truly private when its members can send messages with the team hierarchy.