Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The RMS quote should be seen in the light of the usual message when security researcher talk about the NSA. That is to say if you need protection against state level attackers, relying on a single layer of security technology is insufficient and should always be considered as an exploitable vulnerability that will be broken at some time in the future. Imploring the state actors to act in the same moral way as Snowden is here a last line of defense.

In the context of TLS in Emacs, I don't see how it is a very concerning point in similar style as failing badssl tests. The implied claim that RMS is writing his footer because he thinks the emacs security is faulty is not supported. As such the RMS part of #11 is not supported and do not contribute to the TLS implementation and configuration discussion in regards to Emacs.



I agree with your first paragraph, but I didn't claim RMS thinks Emacs security is faulty. In fact, RMS doesn't seem to be aware of the problems of Emacs' network security. That RMS quote is there to point out the irony that RMS cares enough about security and privacy to prefix all of his emails with that preamble, but not enough to alarm emacs-devs about it. It's well-known that RMS has not been active in Emacs' development for many years now, the responsibility is not on him anymore.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: