Hi, Both my email addresses were unsubscribed from the mailing list. I don't know whether it was on my end, or Greg's. Nor do I know whether it has happened to other people. Crazy-K
On Fri, May 13, 2022 at 02:39:58PM -0400, Undiscussed Horrific Abuse, One Victim of Many wrote:
Hi,
Both my email addresses were unsubscribed from the mailing list.
Karl, It wasn't me, and I didn't get a notification about it. We've seen on the list that anyone can send a forged email to unsubscribe, but then a confirmation is required to actually unsubscribe. Your email, gmkarl@gmail.com, is still subscribed to the cypherpunks list. I just checked. The unsub shenanigans are childish and annoying. I taught my students how to forge an email message in 1998, and of course forged emails are a big part of how spam gets around these days. I'm not impressed by people who are forging unsub emails to the list management software.
I don't know whether it was on my end, or Greg's. Nor do I know whether it has happened to other people.
When an address is unsubscribed, they get a goodbye email from the list software. Did that happen? ~ Greg
On Fri, May 13, 2022, 4:29 PM Greg Newby <gbnewby@pglaf.org> wrote:
On Fri, May 13, 2022 at 02:39:58PM -0400, Undiscussed Horrific Abuse, One Victim of Many wrote:
Hi,
Both my email addresses were unsubscribed from the mailing list.
Karl,
It wasn't me, and I didn't get a notification about it.
We've seen on the list that anyone can send a forged email to unsubscribe, but then a confirmation is required to actually unsubscribe.
Your email, gmkarl@gmail.com, is still subscribed to the cypherpunks list. I just checked.
I had to go through the subscription process to do this for both gmkarl@gmail.com and 0xloem@gmail.com . I was getting bounces, earlier, in response to emails from both email addresses.
The unsub shenanigans are childish and annoying. I taught my students how to forge an email message in 1998, and of course forged emails are a big part of how spam gets around these days. I'm not impressed by people who are forging unsub emails to the list management software.
I don't know whether it was on my end, or Greg's. Nor do I know whether it has happened to other people.
When an address is unsubscribed, they get a goodbye email from the list software. Did that happen?
I'm not seeing this. However, when I looked just now, my client misbehaved, mutating folders on its own. It's been doing that rarely for years, though. It is possible that somebody used access to my email account to unsubscribe me, and then covered their tracks. But it's concerning that this happens at the same time that others are getting unsubscription notices.
~ Greg
When an address is unsubscribed, they get a goodbye email from the list software. Did that happen?
I'm not seeing this.
I ended up finding this for gmkarl@gmail.com but not 0xloem@gmail.com . gmkarl@gmail.com was unsubscribed by someone else at 1058-0500 today, after posting a partial unsub code publicly that I was surprised to receive, which would presumably have required brute forcing the server to use as it was missing trailing digits. 0xloem@gmail.com has bounce notices but no unsubscription notices, and did not receive nor share an unsub code that I saw. It was a little surprising that the bounce notices come from cypherpunks-owner whereas the farewell messages come from cypherpunks-bounces.
Hi Karl. When you get a confirmation code, it means that someone was able to forge your email (this is not hard to do). If you post the confirmation code to the public cypherpunks list, then the same culprit just needs to send that confirmation code in another forged email. So, you should not be posting those confirmation codes! In order to get the confirmation code otherwise, someone would need to intercept your incoming email messages (or, perhaps, the outgoing messages from the list server). That is rather harder than forging an email. ~ Greg On Fri, May 13, 2022 at 05:37:00PM -0400, Karl Semich wrote:
When an address is unsubscribed, they get a goodbye email from the list software. Did that happen?
I'm not seeing this.
I ended up finding this for gmkarl@gmail.com but not 0xloem@gmail.com . gmkarl@gmail.com was unsubscribed by someone else at 1058-0500 today, after posting a partial unsub code publicly that I was surprised to receive, which would presumably have required brute forcing the server to use as it was missing trailing digits. 0xloem@gmail.com has bounce notices but no unsubscription notices, and did not receive nor share an unsub code that I saw.
It was a little surprising that the bounce notices come from cypherpunks-owner whereas the farewell messages come from cypherpunks-bounces.
On Fri, May 13, 2022, 6:02 PM Greg Newby <gbnewby@pglaf.org> wrote:
Hi Karl.
When you get a confirmation code, it means that someone was able to forge your email (this is not hard to do).
If you post the confirmation code to the public cypherpunks list, then the same culprit just needs to send that confirmation code in another forged email.
Yes, I did that within the past few days and was quickly unsubscribed. But the last time I did this I replaced the last 12 characters with the phrase [gently censored] so it would presumably not be usable without work to recover the characters. So, you should not be posting those confirmation codes!
In order to get the confirmation code otherwise, someone would need to intercept your incoming email messages (or, perhaps, the outgoing messages from the list server). That is rather harder than forging an email.
Yes. Is it difficult to verify that the unsubscription and resubscription processes of 0xloem@gmail.com today were normal? With 0xloem, I posted no codes and did not find a farewell notice in my email, but my messages began bouncing until I resubscribed.
~ Greg
When an address is unsubscribed, they get a goodbye email from the
On Fri, May 13, 2022 at 05:37:00PM -0400, Karl Semich wrote: list
software. Did that happen?
I'm not seeing this.
I ended up finding this for gmkarl@gmail.com but not 0xloem@gmail.com . gmkarl@gmail.com was unsubscribed by someone else at 1058-0500 today, after posting a partial unsub code publicly that I was surprised to receive, which would presumably have required brute forcing the server to use as it was missing trailing digits. 0xloem@gmail.com has bounce notices but no unsubscription notices, and did not receive nor share an unsub code that I saw.
It was a little surprising that the bounce notices come from cypherpunks-owner whereas the farewell messages come from cypherpunks-bounces.
On Fri, May 13, 2022 at 06:11:37PM -0400, Karl Semich wrote:
... Is it difficult to verify that the unsubscription and resubscription processes of 0xloem@gmail.com today were normal?
With 0xloem, I posted no codes and did not find a farewell notice in my email, but my messages began bouncing until I resubscribed.
I didn't spot anything suspicious in today's logs. I will keep an eye out. ~ Greg
participants (3)
-
Greg Newby
-
Karl Semich
-
Undiscussed Horrific Abuse, One Victim of Many