From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Robert Pluim Newsgroups: gmane.emacs.bugs Subject: bug#28597: 26.0.60; [Security] Configure should use --without-pop by default Date: Tue, 26 Sep 2017 11:13:38 +0200 Message-ID: <87bmlx4ybh.fsf@gmail.com> References: <87fubaq0dl.fsf@moondust.localdomain> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1506417260 6753 195.159.176.226 (26 Sep 2017 09:14:20 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 26 Sep 2017 09:14:20 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/26.0.60 (gnu/linux) Cc: "N. Jackson" , 28597@debbugs.gnu.org, Richard Stallman To: John Wiegley Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue Sep 26 11:14:14 2017 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dwlwQ-00019u-Nt for geb-bug-gnu-emacs@m.gmane.org; Tue, 26 Sep 2017 11:14:10 +0200 Original-Received: from localhost ([::1]:46313 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dwlwX-00017P-VJ for geb-bug-gnu-emacs@m.gmane.org; Tue, 26 Sep 2017 05:14:17 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:55066) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dwlwM-00014t-NZ for bug-gnu-emacs@gnu.org; Tue, 26 Sep 2017 05:14:10 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dwlwI-0002Hv-HA for bug-gnu-emacs@gnu.org; Tue, 26 Sep 2017 05:14:06 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:51003) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1dwlwI-0002Ho-Cc for bug-gnu-emacs@gnu.org; Tue, 26 Sep 2017 05:14:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1dwlwI-000649-6o for bug-gnu-emacs@gnu.org; Tue, 26 Sep 2017 05:14:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Robert Pluim Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 26 Sep 2017 09:14:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 28597 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 28597-submit@debbugs.gnu.org id=B28597.150641722923292 (code B ref 28597); Tue, 26 Sep 2017 09:14:02 +0000 Original-Received: (at 28597) by debbugs.gnu.org; 26 Sep 2017 09:13:49 +0000 Original-Received: from localhost ([127.0.0.1]:59684 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dwlw5-00063c-Ij for submit@debbugs.gnu.org; Tue, 26 Sep 2017 05:13:49 -0400 Original-Received: from mail-wm0-f52.google.com ([74.125.82.52]:46715) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dwlw4-00063P-Eb for 28597@debbugs.gnu.org; Tue, 26 Sep 2017 05:13:48 -0400 Original-Received: by mail-wm0-f52.google.com with SMTP id m72so5535145wmc.1 for <28597@debbugs.gnu.org>; Tue, 26 Sep 2017 02:13:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:references:gmane-reply-to-list:date:in-reply-to :message-id:user-agent:mime-version; bh=614hwFFugqdLhrn3Gsx7C1hxOcYW1lGPLAwdh0v7pWs=; b=YaJdzq3F6QUsKBB5StBRZvTLdDBT8rY3Yvh5lXTFsWJ4yPWFlxtH3pHKjNHdFFlPU5 AH9L3WfE4+uuRxuRpmrvBY4bnKwuFhwPIBYCO6qSHKn6L1Vld13GS4NQvfotLYvzHup5 kj4LvPBnCfa145SCR3uyeg5QH9l/hHEni4+Y+H8I2DSe6RDTHRgq9cOUjeGwIoRE7YKv 3+KJqqVR+gPJjrWyyl3TTO4n+2vb+pDXJTBjcf2ffcgwTISEUQ0LVhO6bOWcqtAgP7KL 8pENe8q6f5+5Cf+IngloAF+ObZrVhukc1GArSerF/n6sxS14/sIolk8radZDLxjT+6QC /d3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:references :gmane-reply-to-list:date:in-reply-to:message-id:user-agent :mime-version; bh=614hwFFugqdLhrn3Gsx7C1hxOcYW1lGPLAwdh0v7pWs=; b=FXIcqh83b4TznDMQ5MHV0cYEOeCnMUMjv6Gm4wfwo+UeC6A8+fpNWDOEoXXs0/Ko6s 6boQTXJ2QPkeEt1n1ZWtKTNCU1c1nhxaIsoMRC9A2QEyLE8P4n0clmnzBsSzE8AfkxMT AuEh5usrI5qYQRGzf1LiZWq/kOAh9SmNxBhbHSjE7Jw9N0NssM4xlvsEp9ya50RB617P MFgwO4PgmcMh7vqdQxxM8hst+JGjU3IWsbNujQ5bWGucxZ4iyXkjc61twrUIEI7zJkWx PwygQam7FKqJ1Iycbjl3Bi7zAq/OSaRFcqV5U2a6OZf0ESJlXGTm7go7F1tgqyMshPku Gdzg== X-Gm-Message-State: AHPjjUjhc3r6bbHrQ/PjAM/Y75qobK9MzJ+JUzVqENMaSFiPr9U/pE25 z2A2GuRn9z5jqXyCTgL+/5Q= X-Google-Smtp-Source: AOwi7QCIjqnNFYje83NN1/1evf9eGehbMSF4gIWHrpubjPTZJ3zMaaYiuRBvX1Dn3w2YeUcF0ifSjg== X-Received: by 10.80.167.37 with SMTP id h34mr5713456edc.223.1506417222722; Tue, 26 Sep 2017 02:13:42 -0700 (PDT) Original-Received: from rpluim-ubuntu ([149.5.228.1]) by smtp.gmail.com with ESMTPSA id d21sm5434401edb.4.2017.09.26.02.13.41 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 26 Sep 2017 02:13:41 -0700 (PDT) Gmane-Reply-To-List: yes In-Reply-To: (John Wiegley's message of "Mon, 25 Sep 2017 08:21:40 -0700") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:137456 Archived-At: John Wiegley writes: >>>>>> "NJ" == N Jackson writes: > > NJ> Configure issues the following warning: > NJ> configure: WARNING: This configuration installs a 'movemail' program > NJ> that retrieves POP3 email via only insecure channels. > NJ> To omit insecure POP3, you can use './configure --without-pop'. > > NJ> If the warning is true, then --without-pop should be the default, and > NJ> users should have to explicitly request an insecure Emacs with --with-pop. > > You are requesting a change in behavior that is exceedingly old, so I would > like to hear from others what they think about making a change like this. > Given how much less of a thing POP is becoming over the years, I'd be in favor > of changing the default here. I'm sure there are still people stuck with using POP3, but they should be gently incited to move to POP3S or IMAPS the same way people should be steered away from http and TLS < 1.2. Making the default be --without-pop is one way to do that. Regards Robert