From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Paul Eggert Newsgroups: gmane.emacs.devel Subject: Re: Deprecate TLS1.0 support in emacs Date: Tue, 1 Aug 2017 07:45:36 -0700 Organization: UCLA Computer Science Department Message-ID: <4037dc81-4245-6925-842a-2c84a5ba996d@cs.ucla.edu> References: <87o9sp7qok.fsf@gmail.com> <87zic9vk98.fsf@mouse> <87fue17mo5.fsf@gmail.com> <87tw2hvhob.fsf@mouse> <8760ex63hi.fsf@gmail.com> <87fue1v5lr.fsf@mouse> <87shi0tqh3.fsf@gmail.com> <87d18fwl66.fsf@gmail.com> <87tw1rihu0.fsf@mouse> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit X-Trace: blaine.gmane.org 1501598784 25437 195.159.176.226 (1 Aug 2017 14:46:24 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 1 Aug 2017 14:46:24 +0000 (UTC) User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1 Cc: Richard Stallman , emacs-devel@gnu.org To: Lars Ingebrigtsen , Robert Pluim Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Tue Aug 01 16:46:18 2017 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1dcYR7-0006MT-Oi for ged-emacs-devel@m.gmane.org; Tue, 01 Aug 2017 16:46:17 +0200 Original-Received: from localhost ([::1]:43002 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dcYRD-00084E-S8 for ged-emacs-devel@m.gmane.org; Tue, 01 Aug 2017 10:46:23 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:53897) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dcYQb-00083v-AQ for emacs-devel@gnu.org; Tue, 01 Aug 2017 10:45:46 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dcYQX-00046M-1K for emacs-devel@gnu.org; Tue, 01 Aug 2017 10:45:45 -0400 Original-Received: from zimbra.cs.ucla.edu ([131.179.128.68]:47908) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1dcYQW-00044O-Qy; Tue, 01 Aug 2017 10:45:40 -0400 Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id 3EB85160727; Tue, 1 Aug 2017 07:45:38 -0700 (PDT) Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id Ase8CwhARv5l; Tue, 1 Aug 2017 07:45:36 -0700 (PDT) Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id 9545B160726; Tue, 1 Aug 2017 07:45:36 -0700 (PDT) X-Virus-Scanned: amavisd-new at zimbra.cs.ucla.edu Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 8Ain-oKO4-P9; Tue, 1 Aug 2017 07:45:36 -0700 (PDT) Original-Received: from [192.168.1.9] (unknown [47.153.184.153]) by zimbra.cs.ucla.edu (Postfix) with ESMTPSA id 6F9C9160702; Tue, 1 Aug 2017 07:45:36 -0700 (PDT) In-Reply-To: <87tw1rihu0.fsf@mouse> Content-Language: en-US X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [fuzzy] X-Received-From: 131.179.128.68 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:217204 Archived-At: Lars Ingebrigtsen wrote: > it's premature to warn about > things like TLS1.0 in an intrusive manner. There's too many sites out > there that still use that protocol, and warning too much is no help for > our users Last year I would have agreed, but nowadays I think it'd be better to warn about TLS 1.0 somehow. According to https://www.ssllabs.com/ssl-pulse/ from July 2016 to July 2017 TLS v1.2 support climbed from 78.3% to 87.3%, whereas support for TLS v1.0 dropped from 97.3% to to 93.4% as the higher-end sites tighten up security. By the time the next version of Emacs comes out, it looks like a mild warning about TLS v1.0 will be appropriate. For what it's worth, I surf the web mostly via Firefox configured to use only TLS v1.1 or higher, which is stricter than what's being proposed for Emacs. Only once in the last month did I run into problems with this - it was an older internal UCLA website that hadn't been upgraded, and which upgraded immediately after I notified its administrators. So at least for me, a warning from Emacs would have been more helpful, had I been using Emacs.