On Wed, Aug 04, 2010 at 05:53:17PM +0200, Jozef Kutej wrote: > It looks to me as that the Zemanta plugin that is suggesting content is > sending > the text of the blog posts to their service. This plugin is *enabled* by > default > and it was activated only via upgrading. While not everyone uses MovableType > just > for public texts I find it really not a good choice and as a security problem > in a default configuration.
Thanks for pointing this out. It had been mentioned before as a problem but I hadn't fully appreciated that it was sending the content out. I think the best thing to do at this stage is probably to split out the Zemanta plugin into a separate package (with a clear warning about what it does) in order to avoid the risk of delving into the code and making configuration changes deviating from upstream at this stage. Release team, would you approve a new package on this basis? Thanks, Dominic. -- Dominic Hargreaves | http://www.larted.org.uk/~dom/ PGP key 5178E2A5 from the.earth.li (keyserver,web,email) -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org