From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Lars Magne Ingebrigtsen Newsgroups: gmane.emacs.devel Subject: Re: eww Date: Fri, 21 Jun 2013 08:58:09 +0200 Message-ID: References: <87d2rkb1pi.fsf@fleche.redhat.com> <87fvwfa3ev.fsf@fleche.redhat.com> <874ncucrlz@ch.ristopher.com> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: ger.gmane.org 1371797911 24670 80.91.229.3 (21 Jun 2013 06:58:31 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Fri, 21 Jun 2013 06:58:31 +0000 (UTC) Cc: emacs-devel@gnu.org To: Stefan Monnier Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Fri Jun 21 08:58:30 2013 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1UpvIj-0006Pt-7Y for ged-emacs-devel@m.gmane.org; Fri, 21 Jun 2013 08:58:29 +0200 Original-Received: from localhost ([::1]:43199 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UpvIi-0008Su-Us for ged-emacs-devel@m.gmane.org; Fri, 21 Jun 2013 02:58:28 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:45676) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UpvIc-0008Sg-M5 for emacs-devel@gnu.org; Fri, 21 Jun 2013 02:58:26 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1UpvIa-0002eH-22 for emacs-devel@gnu.org; Fri, 21 Jun 2013 02:58:22 -0400 Original-Received: from hermes.netfonds.no ([80.91.224.195]:51456) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1UpvIZ-0002eD-RU for emacs-devel@gnu.org; Fri, 21 Jun 2013 02:58:19 -0400 Original-Received: from cm-84.215.51.58.getinternet.no ([84.215.51.58] helo=stories.gnus.org) by hermes.netfonds.no with esmtpsa (TLS1.0:DHE_RSA_AES_128_CBC_SHA1:16) (Exim 4.72) (envelope-from ) id 1UpvIP-0006sb-GJ; Fri, 21 Jun 2013 08:58:09 +0200 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAGFBMVEWWRC3p2Nf7+fwlAgw9 DRW5eExnHh9+Lyefw+PHAAACd0lEQVQ4jZ2SwW7bMAyGWcSyrlWxtGfvCQpIda8BrMpXBZjiqwcr 1FVDbOn1R8ld1x16GQNEjj7+/EnG8P2LgP8H3cPHnfgK2H/A/fkDTA+fQLf+/CPpjuITePJX8dCV G0HRdeIdiFabs3iPY/mqgM6DlOz9ShzPFXT110HJNyH4Vp7drwLoLAk3uD2LJ0x3JLimCo7O0TlA 04tVa5LdBzwX8MgCZUnumVhjJqNvZrgr4N4W5RJvZ/EDi+Jx9Hd7qUwK1VDaRXkqcsGVOQfiKb2J o1Z+iM7NcHZuGhPqgUrhi/gh6fG2OUTnHG/mZDQI27y4m9RS+pcLdeVc8lqjhinaZRskRerBq5lN ejBv3IA9ZQ8VDMooPYYIlk2gwa39zA6yhlLc68wss3EFN/Wz28GYTq71vICtAdeisxUoxh1zDZ+b MWwcAE8WUgHPFoDyLtSUTBwiMpvaCqBGI8fTEgOEv4DkwKANMHO2gn6F5H313hU8wpWzBqTUw95s v99nUrTsAFLVdII9a0xBIc55O4ChnFtFr1euZwKJFHGh2QGGvoI1YAGRbZAXkCdKeS31+sYMBgMw O4NdQGVoxrGsXTWyp78ok0tICWLIQRtpCKyDWfWA6HWYNGiJi0T6ENAmQhNyJgGCVkoqlIrs12LN kYjXCG2RVg+5htKsxnKTqDtiZgcmZhqcdpIRy6gFlPEz0g7LriDPuYCMWnraSUj08kCbc07XCnhR DFKHZJljbSCTawtgOSkU+SEm6whkzDinWsoPBIzHUsq1mcy3di9VAO7AriHmXBWcp0+A3ppApdaq SEtfgCHAysSI814qeYOaQMtY9aB+4TfvSvVVyN0C/AAAAABJRU5ErkJggg== X-Now-Playing: Jonas Kullhammar Quartet's _The Half Naked Truth 1998-2008 (1)_: "Stormen" X-Hashcash: 1:23:130621:monnier@iro.umontreal.ca::naFuAPz24vGlXnEQ:0000000000000000000000000000000000000onzH X-Hashcash: 1:23:130621:emacs-devel@gnu.org::tkV+w75ijaHjT9+Y:000000000000000000000000000000000000000002qOac In-Reply-To: (Stefan Monnier's message of "Thu, 20 Jun 2013 16:10:54 -0400") User-Agent: Gnus/5.130008 (Ma Gnus v0.8) Emacs/24.3.50 (gnu/linux) X-MailScanner-ID: 1UpvIP-0006sb-GJ MailScanner-NULL-Check: 1372402689.64883@FxyvYPYu/DpS3VwWCfCTDQ X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 80.91.224.195 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:160806 Archived-At: Stefan Monnier writes: > Sounds highly hypothetical. If/when eww can be used to access such > sites, maybe we can start worrying, but then even if you don't keep it > in live data, the sensitive data may linger around in > "garbage/free" memory. If you need to worry about that, you need to > worry about a lot more than that. It's a matter of how big the attack surface is. Leaving the data in easily accessible structures indefinitely is a larger attack surface than killing off the buffer where the offending data is. -- (domestic pets only, the antidote for overdose, milk.) bloggy blog http://lars.ingebrigtsen.no/