Earlier quoted context omitted.
Why do they want this?
[deleted]
You don’t need a password. Posterous fail.
41–50 of 84 posts
Re: You don’t need a password. Posterous fail.
#42Re: You don’t need a password. Posterous fail.
#43It is easy. $ /usr/sbin/sendmail -f dustin@dustincurtis.com dustin@posterous.com Subject: hi Spam spam spam ^D
You don't even need to know the command line, you can often do stuff like that just from Outlook.
Re: You don’t need a password. Posterous fail.
#44Re: You don’t need a password. Posterous fail.
#45It's possible to forge headers in certain circumstances. It's not easy. And this is the first time this has happened. It's ridiculously easy to forge email headers. Headers are manually created whenever programmatically sending email messages. That's how messages can be sent from addresses that don't exist, like devnull@example.com or noreply@yourdomain.com. They don't even send a confirmation email that you have to…
I updated the post to reflect reality. Usually, Posterous catches this stuff and sends an email asking you to confirm that you really are you. They analyze the headers more closely than just looking at the name. For some reason, this didn't work in this case.
Re: You don’t need a password. Posterous fail.
#46Re: You don’t need a password. Posterous fail.
#47Two solutions: 1. Change from "Contributors can post" to "Anyone can post". Counterintuitive, but the first is based on email FROM, the second is moderated. 2. Make a hash as your FROM address. Add it as an alias to send from in Gmail (or whatever you use). Send to posterous from the hash address. Your email address becomes your password.
Re: You don’t need a password. Posterous fail.
#48Two solutions: 1. Change from "Contributors can post" to "Anyone can post". Counterintuitive, but the first is based on email FROM, the second is moderated. 2. Make a hash as your FROM address. Add it as an alias to send from in Gmail (or whatever you use). Send to posterous from the hash address. Your email address becomes your password.
To add an additional outgoing address to Gmail, don't you have to verify that you can receive messages at that account first?
Re: You don’t need a password. Posterous fail.
#49I did it. Sorry Dustin. It really was me. I changed one field in outlook. I realise Posterous requires you to "confirm" the post, I just wanted to see if you had defaulted that requirement to off.
Re: You don’t need a password. Posterous fail.
#50Earlier quoted context omitted.
> "The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password." You'd still be sending your password in the clear, possibly through other peoples mail servers. Not great security.
The perfect is the enemy of the good. There is a trade-off here between security and usability. 99% security is good enough for a lot of purposes and has its place.