From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Lars Magne Ingebrigtsen Newsgroups: gmane.emacs.devel Subject: Re: Bug#766395: emacs/gnus: Uses s_client to for SSL. Date: Sun, 26 Oct 2014 12:42:50 +0100 Message-ID: References: <20141022193441.GA11872@roeckx.be> <87zjcnj2k6.fsf@trouble.defaultvalue.org> <87mw8mzmxj.fsf@mid.deneb.enyo.de> <20141023143702.3897e618@jabberwock.cb.piermont.com> <8761fazkx7.fsf@mid.deneb.enyo.de> <20141023145721.12ed0820@jabberwock.cb.piermont.com> <87vbnay5lf.fsf@mid.deneb.enyo.de> <20141023154223.45f2c9eb@jabberwock.cb.piermont.com> <874muuihjh.fsf@uwakimon.sk.tsukuba.ac.jp> <20141023230048.13f8234a@jabberwock.cb.piermont.com> <87wq7pgpif.fsf@uwakimon.sk.tsukuba.ac.jp> <20141024171421.78720abe@jabberwock.cb.piermont.com> <87h9ys890o.fsf@lifelogs.com> <87egtvdz63.fsf@mid.deneb.enyo.de> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: ger.gmane.org 1414323820 10156 80.91.229.3 (26 Oct 2014 11:43:40 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Sun, 26 Oct 2014 11:43:40 +0000 (UTC) Cc: emacs-devel@gnu.org To: Florian Weimer Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Sun Oct 26 12:43:33 2014 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1XiMEO-0004os-7e for ged-emacs-devel@m.gmane.org; Sun, 26 Oct 2014 12:43:32 +0100 Original-Received: from localhost ([::1]:55978 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XiMEN-0001jM-SO for ged-emacs-devel@m.gmane.org; Sun, 26 Oct 2014 07:43:31 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:43474) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XiMEF-0001fi-G3 for emacs-devel@gnu.org; Sun, 26 Oct 2014 07:43:28 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1XiME7-0004de-Ms for emacs-devel@gnu.org; Sun, 26 Oct 2014 07:43:23 -0400 Original-Received: from hermes.netfonds.no ([80.91.224.195]:39573) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1XiME7-0004ci-Gy for emacs-devel@gnu.org; Sun, 26 Oct 2014 07:43:15 -0400 Original-Received: from cm-84.215.51.58.getinternet.no ([84.215.51.58] helo=stories.gnus.org) by hermes.netfonds.no with esmtpsa (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.72) (envelope-from ) id 1XiMDj-0005jB-6M; Sun, 26 Oct 2014 12:42:51 +0100 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAGFBMVEUAAABMSk0vLjAXFhgD AgQAAAEnISoLCQxqaoXaAAACXElEQVQ4jXVTQXuiMBCdoui1SXbhaoLVKyEtXqmL7TVSca8bs7VX sFX//k5A9mPXlm8YQt43M29eJvB87j1/f/JnuH5895boXpRSvX2PEBL8cKthvln1gPH5I7/HqKzb 0J33ce/glp4GtCIDD62CUeVvY96kaizXMMY86LU/zsQnpBpi5gsAhP8FYC8NXRlGzKFAVtD4DIqq IRZj8eV0ox2rTQlDDW6NlqXYYD3R1zWQFT/x+BNW2BsX86s2YIepPBJ+GkGo5CGy8nqstjFGPNRE LAPkA86GLSuN58QJ5bMtzdqT65VxJzbb7+nxX3VKWHli8STE6xXncUHM/fviLu6Egs6PjNReGvCW VdayQuwsXQ0bpa1i+qIYKp9wjV+1v2pyhIL5O/rU39O+DxUCksRqBN0EXcqrASGW09nofx0F4S/0 sPu9tlbqi1ZFjME0kUHsW4hsPHKUMr9RDOCdsLcYYi9Vk928VwIIs4qpiSAynCdVr0qdpHL/IvYT RUly6/eknO3mbyzalYKZYuprQCsvsitZJ1Zywk3itDo6Vj6MozoJI2YOsL4p1m2EMzDZkCzrQ/KG wM26kwSB6HUrKA1okBpjbrIOyeB0mj0mSZ0c8/qxPtBbcIlccSUfKOXcKEWltMw2iRwUhWtCCaVG IEwJgeKoi6rcgDkSwnGGhAhlygJTdZIwQykiCARmH9D0tk2Fl4LVT9Nw+fNdMblgZnE3WNh0Va7g 8eNbPfg1HSg54ykz9jQ85+ccI8L18ftyOHFTncKdt1m2c1hCFXnVHCcK76GCiZcNWuk3fwCgL4Vf wuBMggAAAABJRU5ErkJggg== X-Now-Playing: Various's _Cold Waves + Minimal Electronics Volume One_: "Eleven Pond - Watching Trees" X-Hashcash: 1:23:141026:emacs-devel@gnu.org::oMwOr1bBgtH/Bcjn:000000000000000000000000000000000000000000KHFm X-Hashcash: 1:23:141026:fw@deneb.enyo.de::ggp2vMOxgGpdtrx6:0cWyI In-Reply-To: <87egtvdz63.fsf@mid.deneb.enyo.de> (Florian Weimer's message of "Sun, 26 Oct 2014 09:15:48 +0100") User-Agent: Gnus/5.130012 (Ma Gnus v0.12) Emacs/25.0.50 (gnu/linux) X-MailScanner-ID: 1XiMDj-0005jB-6M MailScanner-NULL-Check: 1414928571.73959@FjZSnqn1CLUqRlzwPU46yA X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 80.91.224.195 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:175853 Archived-At: Florian Weimer writes: > Uhm, if this happens, the server has been downgraded. The handshake > will fail if a man-in-the-middle attempts to force the use of SSL 3.0, > and both ends support something newer. (As far as I can tell, Emacs > does not implement the vulnerable protocol downgrade code, unlike > browsers.) Oh. Than what's all this fuss about, then? Just the normal churn of "security professional" drama? -- (domestic pets only, the antidote for overdose, milk.) bloggy blog: http://lars.ingebrigtsen.no