|
From: | Paul Eggert |
Subject: | Re: A couple of questions and concerns about Emacs network security |
Date: | Fri, 22 Jun 2018 17:00:08 -0700 |
User-agent: | Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.8.0 |
On 06/22/2018 04:21 PM, Lars Ingebrigtsen wrote:
Paul Eggert <address@hidden> writes:On 06/22/2018 03:00 PM, Jimmy Yuen Ho Wong wrote:1. Can we update the default network security settings?Yes, I would think so, in the master branch. As you say, the current defaults are inappropriate for today's users.They are? In what way?
I was concerned about Emacs Lisp code that calls the gnutls API directly. However, you wrote in a later message that Emacs Lisp code desiring network security should use open-network-stream and use NSM, so perhaps very little (if any) Emacs code is like what I was worried about. If so, the defaults shouldn't matter too much.
I like your suggestion of changing the doc strings of gnutls.el to make it less likely to get future bug reports about this (a la bug#17660 etc.). I'm not expert enough in GnuTLS to know what should go into those doc strings, though.
[Prev in Thread] | Current Thread | [Next in Thread] |