I just got a reminder from the mailman-owner@drupal.org about
my account settings for this mail group.
The email contained my password in clear text!!! This is
completely unacceptable.
- you should never save my password in clear text
- you should never never send it anywhere!
This is something I'd expect from bad practices of the last
century.
As has been mentioned, the fact that this will happen is clearly
stated on the subscription form. This password policy has been
discussed on the Mailman development lists, and the basic argument
is that the list password is protecting low security information, as
all that someone getting this password can do is to mess up your
subscription settings or unsubscribe you from the list. Mailman is
also set up to be totally usable by a user via email and not require
any web access, the process needs to allow for the transmission of
passwords in plain text as their is no other option with email.