> >> Going for three cents (pushing my luck here, I know) why not
> >> just completely disable the ability to PUT subscriber lists,
> >> since there are other ways, reportedly always safer, to do this?
>
> Do the words "COMPLETELY DISABLE THE ABILITY TO PUT SUBSCRIBER LISTS"
> mean anything to you?

I disagree with that, as there are some valid uses for putting the
subscriber list, but i do support making the default not to send the
subscriber list on GET.