From: "Stephen J. Turnbull" <stephen@xemacs.org>
To: "Perry E. Metzger" <perry@piermont.com>
Cc: Florian Weimer <fw@deneb.enyo.de>,
rms@gnu.org, kurt@roeckx.be, Rob Browning <rlb@defaultvalue.org>,
emacs-devel@gnu.org
Subject: Re: Bug#766395: emacs/gnus: Uses s_client to for SSL.
Date: Wed, 29 Oct 2014 11:33:43 +0900 [thread overview]
Message-ID: <87a94f4naw.fsf@uwakimon.sk.tsukuba.ac.jp> (raw)
In-Reply-To: <20141028111032.19366491@jabberwock.cb.piermont.com>
Perry E. Metzger writes:
> Name calling is pretty much always a bad idea in a rational
> discussion. It adds nothing. Defending it as though it were some
> valid form of argumentation is ridiculous.
OK. Have some valid argumentation:
So far I have seen "Perry E. Metzger <perry@piermont.com>"
advocate nothing but extreme positions, often as slogans ("only
one mode, and that is secure"), without backing them up with the
relevant facts on *both* sides of the argument so that others can
judge "the balance" for themselves. Others, whose opinions I have
seen to be substantiated in the past, acknowledge that while there
is some justice to the central claim ("fallback to SSL3 is
dangerous"), there is also controversy among experts about how
serious the danger of SSL3 is in various contexts. Instead of
addressing that in the context of Emacs, he provides anecdotes
about unrelated systems, where the danger is obvious to any
layman, as evidence of how serious things *can* get, but is
unwilling to provide facts about the actual uptake of his
recommendations even in these extreme use cases, despite the fact
that the central vulnerability of his argument is that users will
choose to avoid upgrades because of the inconvenience of the
additional security. I see no reason at present to expect him to
provide balance in the future or account for other values such as
user inconvenience in making his assessments, and therefore
discount his recommendations in spite of his evident technical
expertise and experience.
I recommend to others that they be careful of accepting his policy
recommendations in this context despite his expertise, and demand
more careful argument than he has provided so far, as so far I
have seen only extreme policies appropriate for extreme use cases.
But the policies are not obviously appropriate for Emacs, and I
don't see a valid analogy to Emacs in the use cases.
All OK now, right?
N.B. As you have probably recognized, the above is argument ad
hominem, and does not directly address the issues involved. But that
form of argument is appropriate in this case, because the point is
that, despite your expertise, you haven't addressed them either.
Instead, you have relied on the fact of your expertise (argumentum ad
hominem itself!) and a few specious analogies, rather than the facts
of *this* case.
next prev parent reply other threads:[~2014-10-29 2:33 UTC|newest]
Thread overview: 65+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20141022193441.GA11872@roeckx.be>
2014-10-22 20:02 ` Bug#766395: emacs/gnus: Uses s_client to for SSL Rob Browning
2014-10-22 20:05 ` Rob Browning
2014-10-23 14:03 ` Ted Zlatanov
2014-10-23 15:57 ` Rob Browning
2014-10-24 13:39 ` Ted Zlatanov
2016-02-20 15:28 ` Kurt Roeckx
2016-02-21 2:47 ` Lars Ingebrigtsen
2017-02-22 20:38 ` Bug#766397: " Antoine Beaupre
2017-04-16 17:28 ` Rob Browning
2014-10-22 20:14 ` Stefan Monnier
2014-10-22 21:02 ` Andreas Schwab
2014-10-23 16:49 ` Andreas Schwab
2014-10-23 17:29 ` Lars Magne Ingebrigtsen
2014-10-23 20:36 ` Stefan Monnier
2014-10-24 7:01 ` Lars Magne Ingebrigtsen
2014-10-27 19:42 ` Filipp Gunbin
2014-10-23 16:34 ` Richard Stallman
2014-10-23 18:00 ` Florian Weimer
2014-10-23 18:37 ` Perry E. Metzger
2014-10-23 18:43 ` Florian Weimer
2014-10-23 18:57 ` Perry E. Metzger
2014-10-23 18:59 ` Florian Weimer
2014-10-23 19:11 ` Kurt Roeckx
2014-10-23 19:42 ` Perry E. Metzger
2014-10-23 19:50 ` Florian Weimer
2014-10-23 20:26 ` Perry E. Metzger
2014-10-23 21:05 ` Kurt Roeckx
2014-10-24 2:56 ` Perry E. Metzger
2014-10-23 21:48 ` Stephen J. Turnbull
2014-10-24 3:00 ` Perry E. Metzger
2014-10-24 20:51 ` Stephen J. Turnbull
2014-10-24 21:14 ` Perry E. Metzger
2014-10-24 21:33 ` Lars Magne Ingebrigtsen
2014-10-25 0:36 ` Perry E. Metzger
2014-10-25 15:27 ` Ted Zlatanov
2014-10-25 15:53 ` Lars Magne Ingebrigtsen
2014-10-26 8:15 ` Florian Weimer
2014-10-26 11:42 ` Lars Magne Ingebrigtsen
2014-10-26 12:45 ` Florian Weimer
2014-10-26 1:42 ` Richard Stallman
2014-10-26 7:38 ` Florian Weimer
2014-10-24 21:47 ` Stephen J. Turnbull
2014-10-25 0:42 ` Perry E. Metzger
2014-10-27 17:17 ` Stephen J. Turnbull
2014-10-27 19:39 ` Perry E. Metzger
2014-10-28 7:04 ` Stephen J. Turnbull
2014-10-28 7:45 ` Thien-Thi Nguyen
2014-10-28 8:44 ` Stephen J. Turnbull
2014-10-28 13:31 ` Stefan Monnier
2014-10-28 15:19 ` Perry E. Metzger
2014-10-28 15:33 ` Florian Weimer
2014-10-28 16:20 ` Perry E. Metzger
2014-10-28 16:52 ` Stefan Monnier
2014-10-28 17:11 ` Perry E. Metzger
2014-10-29 3:19 ` Stephen J. Turnbull
2014-10-28 15:10 ` Perry E. Metzger
2014-10-29 2:33 ` Stephen J. Turnbull [this message]
2014-10-29 3:06 ` Perry E. Metzger
2014-10-29 7:28 ` Stephen J. Turnbull
2014-10-29 11:19 ` Perry E. Metzger
2014-10-23 19:03 ` Kurt Roeckx
2014-10-24 13:35 ` Ted Zlatanov
2014-10-25 7:31 ` Richard Stallman
2014-10-25 14:33 ` Perry E. Metzger
2014-10-25 15:49 ` removing SSLv3 support by default from the Emacs GnuTLS integration (was: Bug#766395: emacs/gnus: Uses s_client to for SSL.) Ted Zlatanov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://www.gnu.org/software/emacs/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87a94f4naw.fsf@uwakimon.sk.tsukuba.ac.jp \
--to=stephen@xemacs.org \
--cc=emacs-devel@gnu.org \
--cc=fw@deneb.enyo.de \
--cc=kurt@roeckx.be \
--cc=perry@piermont.com \
--cc=rlb@defaultvalue.org \
--cc=rms@gnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
Code repositories for project(s) associated with this public inbox
https://git.savannah.gnu.org/cgit/emacs.git
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).