<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: When Privacy and Law Collide</title>
	<atom:link href="http://mickc.whizardries.com/archives/2008/06/03/when-privacy-and-law-collide/feed/" rel="self" type="application/rss+xml" />
	<link>http://mickc.whizardries.com/archives/2008/06/03/when-privacy-and-law-collide/</link>
	<description>&#34;Whoever would overthrow the liberty of a nation must begin by subduing the freeness of speech.&#34;</description>
	<lastBuildDate>Fri, 25 Dec 2009 02:15:57 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: John Engler</title>
		<link>http://mickc.whizardries.com/archives/2008/06/03/when-privacy-and-law-collide/comment-page-1/#comment-67876</link>
		<dc:creator>John Engler</dc:creator>
		<pubDate>Mon, 09 Jun 2008 04:15:17 +0000</pubDate>
		<guid isPermaLink="false">http://mickc.whizardries.com/?p=769#comment-67876</guid>
		<description>In July 2007, the FTC held a public hearing about spam, and during that hearing Scott Richter of Media Breakaway LLC, asked the FTC to comment on this same topic, and they confirmed this same thing then: hold on to unsubscribes forever.  If someone unsubscribes, you should make sure you don&#039;t mail them again... 

But that doesn&#039;t mean the data has to be held in plain-text.

It could, and should probably be hashed before being stored, and used in that format (MD5 or SHA-256 would make the most sense - MD5 being most prolific among email service providers, and SHA-256 being the next format that we&#039;ll all move to after we all start using MD5 across the industry).

If you store addresses in a hashed form, they can never be used to actual mailing, and are typically pretty secure, and this need not cause any privacy concerns.

In fact, I&#039;d love to see everyone store suppression lists in MD5 or SHA-256 going forward.  It&#039;d sure save us all a lot of time and effort dealing with suppression list abuse.</description>
		<content:encoded><![CDATA[<p>In July 2007, the FTC held a public hearing about spam, and during that hearing Scott Richter of Media Breakaway LLC, asked the FTC to comment on this same topic, and they confirmed this same thing then: hold on to unsubscribes forever.  If someone unsubscribes, you should make sure you don&#8217;t mail them again&#8230; </p>
<p>But that doesn&#8217;t mean the data has to be held in plain-text.</p>
<p>It could, and should probably be hashed before being stored, and used in that format (MD5 or SHA-256 would make the most sense &#8211; MD5 being most prolific among email service providers, and SHA-256 being the next format that we&#8217;ll all move to after we all start using MD5 across the industry).</p>
<p>If you store addresses in a hashed form, they can never be used to actual mailing, and are typically pretty secure, and this need not cause any privacy concerns.</p>
<p>In fact, I&#8217;d love to see everyone store suppression lists in MD5 or SHA-256 going forward.  It&#8217;d sure save us all a lot of time and effort dealing with suppression list abuse.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Suppression lists at Word to the Wise</title>
		<link>http://mickc.whizardries.com/archives/2008/06/03/when-privacy-and-law-collide/comment-page-1/#comment-67873</link>
		<dc:creator>Suppression lists at Word to the Wise</dc:creator>
		<pubDate>Wed, 04 Jun 2008 13:25:25 +0000</pubDate>
		<guid isPermaLink="false">http://mickc.whizardries.com/?p=769#comment-67873</guid>
		<description>[...] has a post up about how long senders must hold on to that suppression list.           &#171; EEC [...]</description>
		<content:encoded><![CDATA[<p>[...] has a post up about how long senders must hold on to that suppression list.           &laquo; EEC [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
