From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Lars Ingebrigtsen Newsgroups: gmane.emacs.bugs Subject: bug#24489: efaq: security risks Date: Wed, 21 Sep 2016 00:53:13 +0200 Message-ID: References: <7ca8f2ur15.fsf@fencepost.gnu.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: blaine.gmane.org 1474412120 678 195.159.176.226 (20 Sep 2016 22:55:20 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 20 Sep 2016 22:55:20 +0000 (UTC) User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/25.1.50 (gnu/linux) Cc: 24489@debbugs.gnu.org To: Glenn Morris Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Wed Sep 21 00:55:16 2016 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1bmTwW-0007SX-Ao for geb-bug-gnu-emacs@m.gmane.org; Wed, 21 Sep 2016 00:55:12 +0200 Original-Received: from localhost ([::1]:38620 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmTwU-0007ne-Ex for geb-bug-gnu-emacs@m.gmane.org; Tue, 20 Sep 2016 18:55:10 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:44482) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmTwO-0007mr-35 for bug-gnu-emacs@gnu.org; Tue, 20 Sep 2016 18:55:05 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bmTwM-0002QD-3Z for bug-gnu-emacs@gnu.org; Tue, 20 Sep 2016 18:55:03 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:52370) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmTwM-0002Q0-0L for bug-gnu-emacs@gnu.org; Tue, 20 Sep 2016 18:55:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1bmTwL-0007ly-Mk for bug-gnu-emacs@gnu.org; Tue, 20 Sep 2016 18:55:01 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Lars Ingebrigtsen Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Tue, 20 Sep 2016 22:55:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 24489 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: security Original-Received: via spool by 24489-submit@debbugs.gnu.org id=B24489.147441209629864 (code B ref 24489); Tue, 20 Sep 2016 22:55:01 +0000 Original-Received: (at 24489) by debbugs.gnu.org; 20 Sep 2016 22:54:56 +0000 Original-Received: from localhost ([127.0.0.1]:58560 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1bmTwG-0007lc-Ky for submit@debbugs.gnu.org; Tue, 20 Sep 2016 18:54:56 -0400 Original-Received: from hermes.netfonds.no ([80.91.224.195]:48089) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1bmTwF-0007lT-MK for 24489@debbugs.gnu.org; Tue, 20 Sep 2016 18:54:56 -0400 Original-Received: from cm-84.215.1.64.getinternet.no ([84.215.1.64] helo=stories) by hermes.netfonds.no with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from ) id 1bmTw8-0002zc-JE; Wed, 21 Sep 2016 00:54:52 +0200 Face: iVBORw0KGgoAAAANSUhEUgAAADAAAAAwBAMAAAClLOS0AAAAIVBMVEX/Kmb/KWX/J2XKIl// K2ZDE1X/KmL/KGX+KGT/KmhnH2YYvW3gAAACOUlEQVQ4jXWUsW7bMBCG9QwZOreXgA1XEw0cji5B hF0LAYVHSiCkPkCBjrUBIclIE0auYwQbtp6yR1KyjTa9QSL58b//TiRUlP+JQrwdu8JNwfILnAsc P5cnYCG/O2c5vlyAX1HRREXDeaguUm2jLDLrwV+CVQTadiRC3JxBC5oMdANsBcgvwGQOFPxS0RBQ NWVkFv3foK1r11iL5HHZR+d0INAkEBXs7KHUA8AJjKboXF0rlwEORfwISYFJYYG5SWHZ5OGcdo+s nRTNyUO7Dw7OILkzRmDBuYNuBOt5V1V3XTOHqlpwnL+Ie0RBoPoqpJRCCvgkLf8tRC/Epo+pXp8P 4rvYt9jLp4/zB3EgcIxgf72XvdjjRsgWjlIM3wTKewKH9Z1wQuDzIA2KL+KVxngkMFvPCFS9qGTP rwcxu5bHgRRN7o9x/04jgqfjiOXGrwvxo9D0vUJsz6CjEYuNc0+dAfoMdoUlcMs6RkkC0rKPJxsP KgLSxK20kQMCeB7BYwYcMuBxRrekLNiKwS3/QRMwBEwy57GqFUCzuKFUuCWP0ZwTsNwC0gX3mAN8 rqoztBiCwSlODRo0qOp4OtQgja+uMqhV0FopMwLc5pRl8XQTVBsz/cSQFA7z0XYYtApkwhOgMsx4 GVSgPIFKH8P76ZbUBIxOu5MJTkBpE1Q0Dsak5whqRashjAKTa0seFCbgCZgzMHlTthgjVWXw3xiK nm7SW1GkX81yKJfjgCI9i3IX58sRDLRll/gfK5rir9cQfIYAAAAASUVORK5CYII= In-Reply-To: <7ca8f2ur15.fsf@fencepost.gnu.org> (Glenn Morris's message of "Tue, 20 Sep 2016 18:48:06 -0400") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:123490 Archived-At: Glenn Morris writes: > 2) using an Emacs mail client to view HTML mail is a security risk if remote > content is fetched (I think it isn't by default, but this might not > apply to every client) > > 3) viewing remote HTML content (eg with eww or xwidgets) is likewise a > potential security risk. Do you mean privacy risk? -- (domestic pets only, the antidote for overdose, milk.) bloggy blog: http://lars.ingebrigtsen.no