Comment 7 for bug 266821

Revision history for this message
Barry Warsaw (barry) wrote : Re: [Bug 266821] Re: privacy hole in password reminder

On Oct 01, 2012, at 06:51 AM, trampster wrote:

>You should not be able to send me my password in plaintext. Because
>passwords should be stored using an non reversible salted hash.

There are many documented ways to disable password reminders on a per-user,
per-list, or per-site basis. Please read the FAQ.

Mailman 3 removes password reminders and hashes passwords with a configurable
hash algorithm (by default salted sha512).