From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Florian Weimer Newsgroups: gmane.emacs.devel Subject: Re: Bug#766395: emacs/gnus: Uses s_client to for SSL. Date: Tue, 28 Oct 2014 16:33:36 +0100 Message-ID: <87tx2o43an.fsf@mid.deneb.enyo.de> References: <20141022193441.GA11872@roeckx.be> <87zjcnj2k6.fsf@trouble.defaultvalue.org> <87mw8mzmxj.fsf@mid.deneb.enyo.de> <20141023143702.3897e618@jabberwock.cb.piermont.com> <8761fazkx7.fsf@mid.deneb.enyo.de> <20141023145721.12ed0820@jabberwock.cb.piermont.com> <87vbnay5lf.fsf@mid.deneb.enyo.de> <20141023154223.45f2c9eb@jabberwock.cb.piermont.com> <874muuihjh.fsf@uwakimon.sk.tsukuba.ac.jp> <20141023230048.13f8234a@jabberwock.cb.piermont.com> <87wq7pgpif.fsf@uwakimon.sk.tsukuba.ac.jp> <20141024171421.78720abe@jabberwock.cb.piermont.com> <87r3xxgmx2.fsf@uwakimon.sk.tsukuba.ac.jp> <20141024204202.276dbb1f@jabberwock.cb.piermont.com> <8738a95t6b.fsf@uwakimon.sk.tsukuba.ac.jp> <20141027153954.08930677@jabberwock.cb.piermont.com> <87lho04qvn.fsf@uwakimon.sk.tsukuba.ac.jp> <20141028111903.199d44ab@jabberwock.cb.piermont.com> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Trace: ger.gmane.org 1414510447 1550 80.91.229.3 (28 Oct 2014 15:34:07 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Tue, 28 Oct 2014 15:34:07 +0000 (UTC) Cc: rms@gnu.org, kurt@roeckx.be, emacs-devel@gnu.org, Stefan Monnier , "Stephen J. Turnbull" , Rob Browning To: "Perry E. Metzger" Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Tue Oct 28 16:33:59 2014 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1Xj8mV-0000et-Hk for ged-emacs-devel@m.gmane.org; Tue, 28 Oct 2014 16:33:59 +0100 Original-Received: from localhost ([::1]:39852 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Xj8mV-0002JP-5H for ged-emacs-devel@m.gmane.org; Tue, 28 Oct 2014 11:33:59 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:45823) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Xj8mN-0002JH-5j for emacs-devel@gnu.org; Tue, 28 Oct 2014 11:33:57 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Xj8mH-0001TF-21 for emacs-devel@gnu.org; Tue, 28 Oct 2014 11:33:51 -0400 Original-Received: from albireo.enyo.de ([46.237.207.196]:41355) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Xj8mG-0001T3-SN; Tue, 28 Oct 2014 11:33:44 -0400 Original-Received: from [172.17.203.2] (helo=deneb.enyo.de) by albireo.enyo.de with esmtps (TLS1.2:DHE_RSA_AES_128_CBC_SHA1:128) id 1Xj8m8-00020i-Rv; Tue, 28 Oct 2014 16:33:36 +0100 Original-Received: from fw by deneb.enyo.de with local (Exim 4.80) (envelope-from ) id 1Xj8m8-0003c3-J7; Tue, 28 Oct 2014 16:33:36 +0100 In-Reply-To: <20141028111903.199d44ab@jabberwock.cb.piermont.com> (Perry E. Metzger's message of "Tue, 28 Oct 2014 11:19:03 -0400") X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x [generic] [fuzzy] X-Received-From: 46.237.207.196 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:175923 Archived-At: * Perry E. Metzger: > The trick is to make sure it isn't used as an instrument to prevent > ordinary people from booting software of their choice, but rather is > used as an instrument to assure that when they boot the software of > their choice, they're actually getting that and not malware. None of the existing boot verification technologies provides this. It's also difficult to reconcile this with full user autonomy=E2=80=94if the user can load previously untrusted key material (and especially if this is an expected step during installation of a free operating system), the firmware can no longer warn about malicious keys and malicious software (because the user has replaced the trust root).