This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Mailman retirement to Google Groups

From OWASP
Revision as of 16:16, 26 February 2019 by Mtesauro (talk | contribs) (Saved after adding a bunch of content for CYA purposes)

Jump to: navigation, search

Overview

Since very early in OWASP's history, Mailman has been used to facilitate communication between various members of the community. While Mailman has served the community well for years, the decision has been made to migrate from a self-hosted Mailman installation to Google Groups. The migration will allow the community to continue to have an email address to reach a particular segments of the community just like Mailman provides but without the administrative burden of running a server for Mailman. The reasons for this migration were stated at length on the leaders list here but are summarized below in no particular order:

  • Mailman is old software and doesn't follow current security best practices.
    • It sends passwords in the clear which has been repeatedly pointed out by the community for quite some time as noted here.
    • It has a single shared password for overall site administration for the staff to use to oversee the installation
    • If a mail list has 2+ list owners, they must share a password for managing the list
  • Mailman has an extremely dated UI/web interface. This makes OWASP appear out of date/out of touch to new, potential community members
  • Since the Foundation has a very small staff, administering a server takes away staff time from focusing on OWASP's mission / core purpose.
  • The Anti-SPAM gateway service from Barracuda, which was previously donated, is ending on March 24th, 2019.
  • Due to the current climate of increased privacy and the existence of the GDPR, the migration will allow the membership in our lists to be reviewed/audited by the current user base.

Project Links

Goals

Include top-level goals of the project in an ordered list Give thought to the ordering of goals. Revenue, attendance, launch date Make sure goals are measurable from undisputed source

Milestones

  • In an unordered list (billeted) list major milestones in chronological order
  • Use the syntax of 2019-01-19, Milestone name [Name of Owner]
  • When milestones are completed, mark them as such with ??
  • A milestone isn’t everyone’s to-do list, it is the high level tasks of the project
  • If you have more than 20 milestones, you’re being too granular

Communications


Leadership

  • unordered list of each leader and a hyperlink to their email address.