ietf
[Top] [All Lists]

Re: e-mail password reminders discontinued

2015-05-20 06:46:58
FYI, here is a bit more detail regarding the issues we encountered:

The main issue:

What we discovered is that it's not possible, in Mailman, to turn this off 
for everyone whilst still allowing individuals to selectively turn it back 
on.  We had thought that was the case initially, but it turned out Mailman 
doesn't behave that way.  This is why we're back in this position now.

History of events:

1. There was a discussion and decision to move the default to “do not send”
 
2. The change was implemented, and we assumed that people can edit their 
settings

We turned the "send reminders" but to "off" for every individual subscriber.  
They were able to turn them on again through the Mailman admin interface.  We 
also changed a Mailman setting that was supposed to make this the default for 
new subscriptions to new or existing lists.

We found out that the default setting did not work, which is to say that new 
subscriptions to lists were enabled for password reminders by default.

3. Some months later, in 2014, another setting was changed but accidentally 
caused the reminders to not be sent despite settings otherwise

The setting was supposed to turn the password reminder default to off by 
list.  This was thought to turn off the default option, but still allow users 
to turn them on. What actually happened is that this turned the password 
reminders for every member of that list, regardless of their individual 
option.

4. The setting was reverted

We turned that bit back off on the lists, so that individuals who had opted 
for automatic reminders would get them again.

5. Subscriber growth

In the meantime, while all of the above was transpiring, we were gathering 
new subscriptions to various lists.  When the reminders processed after the 
configuration change, tens of thousands of reminders were sent.

What we have discovered through this process is that there is a key element 
missing in Mailman, and that is the ability to make the "send password 
reminders" bit default to off for new subscriptions. The result of this is 
that if we go through and do a mass reset of those settings, we will still 
over time build up a very large group of automatic reminders, with all the 
concomitant issues that come from bulk mailing tens of thousands of 
reminders.  ISOC encountered the same issues and ended up turning off the 
automatic reminders.

Attachment: signature.asc
Description: Message signed with OpenPGP using GPGMail

<Prev in Thread] Current Thread [Next in Thread>