I too think that this is a great idea, however, it might be easier to create a separate
security@ mailing list now (and automatically?) subscribe users rather than posting
everything to the users@ mailing list; even if there is little traffic right now, this may
increase/change and it'd be easier to grow the service if its segregated from the
start.
I also can't remember what the new customer signup form for Bitfolk is like, but
recently filled in a form (from another organisation) with a single checkbox labelled
"…We like to keep you informed about services, campaigns, events, publications and
new initiatives…" - obviously more granular control is better for the user and I
think that given the option most users will opt-in (or can be auto-enrolled in accordance
with terms & conditions), knowing full-well that they actually want what they're
signing-up for rather than facing the daunting single tick box which gives the user
"all or nothing".
On 7 Dec 2012, at 02:19, Andy Smith <andy(a)bitfolk.com> wrote:
So I was contemplating posting an email thread to this
("users")
list every time we become aware of a customer compromise, and I was
wondering what you thought of that idea.