Earlier versions of Sympa require a parameter named cookie in sympa.conf
configuration file.
This parameter was used to make some identifiers generated by the system
unpredictable. For example, it was used as following:
There were the following problems with the use of this parameter.
- This parameter, for its purpose, should be different for each
installation, and once set, it cannot be changed. As a result, some sites
have been operating without setting this parameter. This completely
invalidates the security measures described above.
- Even if this parameter is properly set, it may be considered not being
strong enough against brute force attacks.