Issue 50 - All IssueZilla passwords are being posted to the mailing lists
Summary: All IssueZilla passwords are being posted to the mailing lists
Status: CLOSED NOT_AN_OOO_ISSUE
Alias: None
Product: Infrastructure
Classification: Infrastructure
Component: Bugzilla (show other issues)
Version: current
Hardware: All All
: P1 (highest) Trivial (vote)
Target Milestone: ---
Assignee: Unknown
QA Contact: issues@www
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2000-10-25 00:15 UTC by bill.roth
Modified: 2003-12-27 10:23 UTC (History)
2 users (show)

See Also:
Issue Type: DEFECT
Latest Confirmation in: ---
Developer Difficulty: ---


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description bill.roth 2000-10-25 00:15:58 UTC
The should be removed. Seems like a security hole to me.
Comment 1 Unknown 2000-10-25 00:36:14 UTC
What mailing lists? Please be specific. There are many mailing lists.
One way of specifying more rigorously is to use the URL field above 
to reference the mail-archive dir or the speicfic message w/ a problem.

If you mean, IZ had in the past posted passwords to
bugs@<project>.openoffice.org, that is the result of operator error
in Hamburg as they did not know of 
    http://www.openoffice.org/issues/editusers.cgi?action=add
which is a way of creating new lists w/o posting passwords...

However, now that the lists have been setup, this should not be a problem
anymore. Also, the Hamburg employee who caused the password messages to
go out claims he has changed all the posted passwords. Furthermore, these
bugs@<project>.openoffice.org lists have no privileges whatsoever, so there
shouldn't be a security concern with this issue.

I am therefore marking this defect as "invalid" . please reopen if
for some reason any of your concerns arent' being addressed here.

Below is some previous mail on this issue that I wrote. (edited to remove 
email addresses and quotation of post i'm replying to, since the author
of that post hasn't given me permission to repost his mail (i haven't asked)):
--------------------------------
Subject: Re: [tools-bugs] Your OpenOffice Issuezilla password. 
Date: Wed, 18 Oct 2000 11:49:30 -0700
From: "Niels P. Mayer" <npm@collab.net>

[...]

These are mailing lists and "role accounts". You should never log in to a
mailing list in issuezilla -- it simply doesn't make any sense. People
accepting bugs or assigning bugs need to do it as themselves not as a
virtual user or role account. Issue-tracking and workflow requires making
personal requests and commitments that do not make sense unless you're
putting your own name (or at least personal email) on the line.

[ why message went to dev@tools.oo.org ...]

No. The msssage should have gone to bugs@tools, and it appears to have been
sent there. Replies to bugs@<project> should go to dev@<project> so perhaps
that's what happened.

However, when creating new mailing lists-based "pseudo-users" one needn't
have them send mail at all. An admin-level user (e.g. Stefan T or Michael B
or anybody with issuezilla parameter "Editusers" set on their account) can
use the "add new user" form
(http://www.openoffice.org/issues/editusers.cgi?action=add) and set the
password directly, preferably to something nobody will ever guess,
remember, or, use, since you're not supposed to login to mailing list
accounts in the first place.

Furthermore, remeber when setting up mailing-list "pseudo-users" in
IssueZilla, these users should have no privileges whatsoever. They should
not be able to change the status of an issue, or edit any aspect of an
issue, or accept an issue. Specifically, all the following parameters
should be OFF:
       Canconfirm: Can confirm an issue.
       Creategroups: Can create and destroy groups.
       Editcomponents: Can create, destroy, and edit components.
       Editissues: Can edit all aspects of any issue.
       Editkeywords: Can create, destroy, and edit keywords.
       Editusers: Can edit or disable users
       Tweakparams: Can tweak operating parameters

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
>> Niels Mayer (npm@collab.net)       http://www.cybertribe.com/mayer  <<
>>                    CollabNet, San Francisco, CA                     <<
>>  Collab.Net is hiring!  Go to http://www.collab.net/jobs for info.  <<
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Comment 2 stx123 2000-10-25 10:58:15 UTC
And the passwords have been changed...
Comment 3 stx123 2000-11-13 11:04:54 UTC
No further action eeded