bug-gnu-emacs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#28597: 26.0.60; [Security] Configure should use --without-pop by def


From: Robert Pluim
Subject: bug#28597: 26.0.60; [Security] Configure should use --without-pop by default
Date: Tue, 03 Oct 2017 16:55:51 +0200
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/26.0.60 (gnu/linux)

nljlistbox2@gmail.com (N. Jackson) writes:

> At 16:20 -0700 on Monday 2017-10-02, Paul Eggert wrote:
>>
>> On 10/02/2017 11:47 AM, Eli Zaretskii wrote:
>>
>>> nagging users each time they invoke movemail to fetch via POP3
>>> is IMO unacceptable.
>>
>> Yes, that suggestion is problematic.
>
> Just for the record, I explicitly stated in my suggestion to warm
> the user (rather than just the builder) that Emacs should _not_ nag
> the user every time.
>
> I was thinking of disabling the commands in question in the case
> that they will be insecure and prompting along the lines of:
>
>   You have typed abc, invoking disabled command xyz.
>

Except that there's not a single specific command that retrieves mail
via POP3, it's wired into the guts of rmail, and I'd rather not touch
that.

This is all starting to sound like overkill compared to simply warning
the builder, especially since people who package emacs can easily add
GNU Mailutils as a dependency, and people who build their own emacs
should read and react to the warning messages that I proposed earlier.

Robert





reply via email to

[Prev in Thread] Current Thread [Next in Thread]