Am 17.05.21 um 14:17 schrieb Richard Damon:
> On 5/17/21 8:00 AM, Magnus Harlander wrote:
>> Hi,
>>
>> have you ever got an email containing lots of email addresses
>> including your
>> own in the TO or CC field or somewhere else in the mail body?
>>
>> I think, this happens for different reasons:
>>
>> - people sending emails to many recipients don't know or don't care
>> how to do that
>>   properly
>> - people dont' know abount BCC
>> - people forgot to use BCC instead of CC
>> - email/calendar programs like outlook/exchange send invitations without
>>   the senders interaction including all invitees in the to/cc as well
>>   as in the text/calendar mime-body part containung an icalendar event
>> - people replying to all header recipients after receiving such mails
>>
>> I don't like that and have thought about a solution:
>> ...
>> Is this really a good idea?
>>
>> \Magnus
> I think the biggest problem with your solution is that sometimes it
> really isn't a 'problem' and is the right answer. It might be desirable
> to let the group be able to 'Reply-All' to the message to discuss some
> things related to it.
>
> This means breaking it at the server level has REALLY broken it. You
> don't want to prohibit at the server level things that you might want to
> allow in some cases. This might make a great feature at the MDA level,
> where it pops up a warning that the visable recipient list is long, and
> ask if you want to make it a BCC: list instead, but enforcing this
> breaks some workflows.
>
> Unless you really want to prohibit that activity, you can't do it at the
> server level.
>
I see your point. A few ideas on that:

- MDA/MUA would definitely be the better place to do that. There are
just so many
  of them - and we should tell microsoft...
- general scrubbing of to/cc could be switched off by config, so it
happens only
  if there is an ical attachment found. This makes sence because in this
case
  you have no chance as a user to avoid the disclosure
- we could have an opt-in or opt-out header field or a subject keyword
like NOFILTER.
  I know, this is probably only a solution for nerds ....
- there could be a whitelist of senders
- btw. the number of addresses allowed in cc and to is also a config option.

\Magnus

-- 
Dr. Magnus Harlander
Mail: har...@harlan.de
Web: www.harlan.de
Stiftung: www.harlander-stiftung.de
Ceterum censeo bitcoin esse delendam!

Attachment: OpenPGP_signature
Description: OpenPGP digital signature

Reply via email to