emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: A couple of questions and concerns about Emacs network security


From: Lars Ingebrigtsen
Subject: Re: A couple of questions and concerns about Emacs network security
Date: Sat, 23 Jun 2018 11:57:08 +0200
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/27.0.50 (gnu/linux)

Stefan Monnier <address@hidden> writes:

>> I like your suggestion of changing the doc strings of gnutls.el to make it
>> less likely to get future bug reports about this (a la bug#17660 etc.). I'm
>> not expert enough in GnuTLS to know what should go into those doc
>> strings, though.
>
> Maybe an alternative is to change those default settings to be extremely
> strict, and loosen them as needed/appropriate when we go through the NSM.

Hm...  I may be misunderstanding what you mean here, but do you mean
doing things like set `gnutls-min-prime-bits' to, say, 4096 (extremely
strict :-)), and then have the NSM `medium' `network-security-level'
change the setting back to 256 and reconnect?

If so, that would to me seem to achieve little in practice and just make
all (TLS) network connections slower...

-- 
(domestic pets only, the antidote for overdose, milk.)
   bloggy blog: http://lars.ingebrigtsen.no



reply via email to

[Prev in Thread] Current Thread [Next in Thread]