From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Marcin Borkowski Newsgroups: gmane.emacs.devel Subject: Re: Closing a privilege escalation Date: Fri, 27 Apr 2018 11:50:22 +0200 Message-ID: <87sh7hkmg1.fsf@mbork.pl> References: NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1524824518 16514 195.159.176.226 (27 Apr 2018 10:21:58 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Fri, 27 Apr 2018 10:21:58 +0000 (UTC) User-Agent: mu4e 1.1.0; emacs 27.0.50 Cc: Lars Ingebrigtsen , emacs-devel@gnu.org To: rms@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Fri Apr 27 12:21:53 2018 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fC0Vk-0004D6-30 for ged-emacs-devel@m.gmane.org; Fri, 27 Apr 2018 12:21:52 +0200 Original-Received: from localhost ([::1]:47089 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fC0Xq-0001bP-RY for ged-emacs-devel@m.gmane.org; Fri, 27 Apr 2018 06:24:02 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:40399) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fC02c-0004qV-7S for emacs-devel@gnu.org; Fri, 27 Apr 2018 05:51:47 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fC02Y-0000Ud-7a for emacs-devel@gnu.org; Fri, 27 Apr 2018 05:51:46 -0400 Original-Received: from mail.mojserwer.eu ([195.110.48.8]:60504) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fC02X-0000MW-Vz; Fri, 27 Apr 2018 05:51:42 -0400 Original-Received: from localhost (localhost [127.0.0.1]) by mail.mojserwer.eu (Postfix) with ESMTP id 6248EE64B3; Fri, 27 Apr 2018 11:51:13 +0200 (CEST) X-Virus-Scanned: Debian amavisd-new at mail.mojserwer.eu Original-Received: from mail.mojserwer.eu ([127.0.0.1]) by localhost (mail.mojserwer.eu [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JahXzJNf24_X; Fri, 27 Apr 2018 11:51:09 +0200 (CEST) Original-Received: from localhost (apn-77-112-140-138.dynamic.gprs.plus.pl [77.112.140.138]) by mail.mojserwer.eu (Postfix) with ESMTPSA id 0A453E6486; Fri, 27 Apr 2018 11:51:08 +0200 (CEST) In-reply-to: X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] [fuzzy] X-Received-From: 195.110.48.8 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.org gmane.emacs.devel:224917 Archived-At: On 2018-04-26, at 23:05, Richard Stallman wrote: > to arrange to take advantage later. One way is by editing .emacs > so that it will do something bad next time the user runs Emacs under sudo. Out of curiosity: why would anyone run Emacs under sudo? Shouldn't it be disabled? (Possibly, there might be option, called e.g. --i-explicitly-do-ask-for-troubles, which could enable that.) Best, -- Marcin Borkowski http://mbork.pl