From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Lars Magne Ingebrigtsen Newsgroups: gmane.emacs.devel Subject: Re: GnuTLS for W32 Date: Fri, 06 Jan 2012 04:15:28 +0100 Organization: Programmerer Ingebrigtsen Message-ID: References: <87boqk3q69.fsf@uwakimon.sk.tsukuba.ac.jp> <87aa634st8.fsf@uwakimon.sk.tsukuba.ac.jp> <87fwfvsgfv.fsf@wanadoo.es> <877h17scdo.fsf@wanadoo.es> <87hb0b77nr.fsf@lifelogs.com> <8739bvs27m.fsf@wanadoo.es> <87ty4b4329.fsf@lifelogs.com> <87hb0b3yoe.fsf@lifelogs.com> <6ED011D5-E185-44C6-BB31-A445A4E5F83A@gmail.com> <87wr976otx.fsf@lifelogs.com> <87ipkq6yy5.fsf@lifelogs.com> <87boqi6tzz.fsf@linux-hvfx.site> <87ehve3ul8.fsf@lifelogs.com> <87pqey6m0o.fsf@linux-hvfx.site> <87zke129sy.fsf@lifelogs.com> NNTP-Posting-Host: lo.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: dough.gmane.org 1325819758 15074 80.91.229.12 (6 Jan 2012 03:15:58 GMT) X-Complaints-To: usenet@dough.gmane.org NNTP-Posting-Date: Fri, 6 Jan 2012 03:15:58 +0000 (UTC) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Fri Jan 06 04:15:51 2012 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([140.186.70.17]) by lo.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1Rj0HW-0005m7-Qv for ged-emacs-devel@m.gmane.org; Fri, 06 Jan 2012 04:15:51 +0100 Original-Received: from localhost ([::1]:40523 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rj0HW-0002Fb-8Q for ged-emacs-devel@m.gmane.org; Thu, 05 Jan 2012 22:15:50 -0500 Original-Received: from eggs.gnu.org ([140.186.70.92]:55535) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rj0HS-0002FL-Vg for emacs-devel@gnu.org; Thu, 05 Jan 2012 22:15:47 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Rj0HR-0001Td-Lo for emacs-devel@gnu.org; Thu, 05 Jan 2012 22:15:46 -0500 Original-Received: from lo.gmane.org ([80.91.229.12]:42343) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rj0HR-0001Sw-9H for emacs-devel@gnu.org; Thu, 05 Jan 2012 22:15:45 -0500 Original-Received: from list by lo.gmane.org with local (Exim 4.69) (envelope-from ) id 1Rj0HN-0005j2-KN for emacs-devel@gnu.org; Fri, 06 Jan 2012 04:15:41 +0100 Original-Received: from cm-84.215.51.58.getinternet.no ([84.215.51.58]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Fri, 06 Jan 2012 04:15:41 +0100 Original-Received: from larsi by cm-84.215.51.58.getinternet.no with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Fri, 06 Jan 2012 04:15:41 +0100 X-Injected-Via-Gmane: http://gmane.org/ Mail-Followup-To: emacs-devel@gnu.org Original-Lines: 26 Original-X-Complaints-To: usenet@dough.gmane.org X-Gmane-NNTP-Posting-Host: cm-84.215.51.58.getinternet.no Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAGFBMVEXZ1sH5+N8+OkJybGsK BxITEB0EAwqqpplPQ7p0AAACV0lEQVQ4jW2Sz27jIBDGcawVV2gPue6Og3xtQBb3CPIAjukTpDk7 tiJev99A3G5XO4pkMj+++ccI/R+TRL34aRWslC5C5rxmmM8rvs1foHfLYqnzzrvlCaRl4NxqBxo7 5zoLACR9XgBW562l0VkALyTyLCmxwjuXcRsKBPNZiL0BGIUs5t0K4KzPs1hMCjEBCCFb1MSAoJ5R 0xQCg1l8gc7lhlMUAALAfmdQdk5PwN2V6wWQX+GfNmDJEpF1aSRniyBw4fNagWPQrUVQFRvAZeqW TYGmSg4QQmMdmQoEFHP7BVIHXQml8ApNW4uyBbRVoUUjdFF0tgAvTAVsL1Tm7kab+n625guozBN2 c96jupzNtAGN97HdXa/SdG9SOTLfQFGvjgOd+qZpZX4EgadkKCTd1eUQgp91vi9p4jZgePle7wJi 51m5fAgTuuChyLwe1eNkLiYL1VpO3nCHZbvc0nu981qtpY8K0P1CGcncHy1MGUk1KdTgUMgr3XUb Yh1JAY0efNtoQ0f1q4Jtm9VAXaNkbubFbCCzoN2lN4Syd71XeZhK56X748tF5HlIvzEdhD7AKRko vW/202kwZoJQyUlo+36Z67weIQ54pPgmcBT7c0jk2f+KlLwIMfQSOV7D7SONfasVJhimiK5j4E18 ucFC7Dz7Q4rpNNU+CriGOBV/Mml8lGMBV/zO0IU04nqRVhDP15TOtziadA1PEzuAj/fI2xbCaL9B 4lDv+M/7d6LD7YnElZOfubKaHdnOXI24bYAZ6n6efgKuo342xbfFTfwvuJ6rIHwCkVQATg5F4S0A AAAASUVORK5CYII= Mail-Copies-To: never X-Now-Playing: Suzanne Vega's _Close-Up, Volume 1: Love Songs_: "Stockings" User-Agent: Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.92 (gnu/linux) Cancel-Lock: sha1:K9AU8DyOoBNisxCoS8ltKZrY6zs= X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.6 (newer, 3) X-Received-From: 80.91.229.12 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:147384 Archived-At: Ted Zlatanov writes: > The user doesn't know, usually, that there's been a critical GnuTLS > release that affects them. Unlike normal updates, ignoring this can > actually compromise their security, not just corrupt or expose their > data. $ ssh gnu.org Checking for updates to ssh... please wait Apparently somebody has made a brute-force attack feasible against the encryption algorithm ssh was going to use against the remote server. Download and install a new version of ssh? > This is a crucial distinction. So I want Emacs to notify the > user their GnuTLS is out of date, or else something else should > (e.g. the self-contained GnuTLS updater for W32 I proposed). I don't really see that there's much of a difference between bugs in libgnutls and in the Emacs binary proper. If a major security hole was discovered in Emacs, then presumably a new Emacs release would be made. If a major libgnutls hole was discovered, then presumably someone would zip up a new Windows release. -- (domestic pets only, the antidote for overdose, milk.) bloggy blog http://lars.ingebrigtsen.no/