From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: "Perry E. Metzger" Newsgroups: gmane.emacs.devel Subject: Re: A couple of questions and concerns about Emacs network security Date: Thu, 5 Jul 2018 11:10:21 -0400 Message-ID: <20180705111021.3c1459bd@jabberwock.cb.piermont.com> References: NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Trace: blaine.gmane.org 1530803336 10255 195.159.176.226 (5 Jul 2018 15:08:56 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Thu, 5 Jul 2018 15:08:56 +0000 (UTC) Cc: Lars Magne Ingebrigtsen , Paul Eggert , Jimmy Yuen Ho Wong , Emacs developers To: Noam Postavsky Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Thu Jul 05 17:08:51 2018 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fb5sJ-0002WK-Ee for ged-emacs-devel@m.gmane.org; Thu, 05 Jul 2018 17:08:51 +0200 Original-Received: from localhost ([::1]:53240 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fb5uO-00059s-NA for ged-emacs-devel@m.gmane.org; Thu, 05 Jul 2018 11:11:00 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:41843) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fb5tq-00059l-Cc for emacs-devel@gnu.org; Thu, 05 Jul 2018 11:10:27 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fb5tm-0001tb-59 for emacs-devel@gnu.org; Thu, 05 Jul 2018 11:10:26 -0400 Original-Received: from hacklheber.piermont.com ([166.84.7.14]:35174) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1fb5tl-0001tO-Tf for emacs-devel@gnu.org; Thu, 05 Jul 2018 11:10:22 -0400 Original-Received: from snark.cb.piermont.com (localhost [127.0.0.1]) by hacklheber.piermont.com (Postfix) with ESMTP id 676D0217; Thu, 5 Jul 2018 11:10:21 -0400 (EDT) Original-Received: from jabberwock.cb.piermont.com (jabberwock.cb.piermont.com [10.160.2.107]) by snark.cb.piermont.com (Postfix) with ESMTP id 3EE542DEE47; Thu, 5 Jul 2018 11:10:21 -0400 (EDT) In-Reply-To: X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 166.84.7.14 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:226953 Archived-At: On Fri, 22 Jun 2018 22:17:56 -0400 Noam Postavsky wrote: > Can we bump gnutls-min-prime-bits to 1024 on the release branch? I > know it has a reference to Bug#11267 which describes some mail > server that works only with 256 bits primes, but surely people > using such software can set the option themselves. I mean, a 256 > bit DH prime is just a toy example, not real crypto. It's > inappropriate for yesterday's users. Even 1024 is probably a bit > low, but at least it's something. That's too low, but it is the minimum in all modern browsers. Perry -- Perry E. Metzger perry@piermont.com