From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.emacs.gnus.general/63684 Path: news.gmane.org!not-for-mail From: Richard Stallman Newsgroups: gmane.emacs.devel,gmane.emacs.gnus.general Subject: Re: Security flaw in pgg-gpg-process-region? Date: Wed, 06 Sep 2006 04:49:03 -0400 Message-ID: References: <9c79059a-61a9-4fa4-8376-638753320a14@well-done.deisui.org> <4aaf7080-0e3d-4a75-aff5-f9d5bcd0437f@well-done.deisui.org> <87fyjz2gaj.fsf@pacem.orebokech.com> <8980fd83-08b6-4aef-97f2-a659cd2eadb2@well-done.deisui.org> <180dcf90-af71-4f6d-b0d0-57d364218c73@broken.deisui.org> <6d43cc51-e472-405c-b372-dba7ef5a914d@broken.deisui.org> <2234179d-6686-49f4-b38b-b06788041225@well-done.deisui.org> Reply-To: rms@gnu.org NNTP-Posting-Host: main.gmane.org Content-Type: text/plain; charset=ISO-8859-15 X-Trace: sea.gmane.org 1157532661 8685 80.91.229.2 (6 Sep 2006 08:51:01 GMT) X-Complaints-To: usenet@sea.gmane.org NNTP-Posting-Date: Wed, 6 Sep 2006 08:51:01 +0000 (UTC) Cc: ding@gnus.org, Reiner.Steib@gmx.de, emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Wed Sep 06 10:50:59 2006 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([199.232.76.165]) by ciao.gmane.org with esmtp (Exim 4.43) id 1GKt7V-0006tS-HA for ged-emacs-devel@m.gmane.org; Wed, 06 Sep 2006 10:50:53 +0200 Original-Received: from localhost ([127.0.0.1] helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1GKt7U-0000I7-SC for ged-emacs-devel@m.gmane.org; Wed, 06 Sep 2006 04:50:52 -0400 Original-Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1GKt5o-0006ly-TN for emacs-devel@gnu.org; Wed, 06 Sep 2006 04:49:09 -0400 Original-Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1GKt5n-0006kB-Mm for emacs-devel@gnu.org; Wed, 06 Sep 2006 04:49:07 -0400 Original-Received: from [199.232.76.173] (helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1GKt5n-0006jm-D3 for emacs-devel@gnu.org; Wed, 06 Sep 2006 04:49:07 -0400 Original-Received: from [199.232.76.164] (helo=fencepost.gnu.org) by monty-python.gnu.org with esmtp (Exim 4.52) id 1GKt5u-0002S1-6Q for emacs-devel@gnu.org; Wed, 06 Sep 2006 04:49:14 -0400 Original-Received: from rms by fencepost.gnu.org with local (Exim 4.34) id 1GKt5j-0005Jy-Uv; Wed, 06 Sep 2006 04:49:04 -0400 Original-To: Daiki Ueno In-reply-to: <2234179d-6686-49f4-b38b-b06788041225@well-done.deisui.org> (message from Daiki Ueno on Tue, 05 Sep 2006 02:45:53 +0900) X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:59417 gmane.emacs.gnus.general:63684 Archived-At: First, in (1) he didn't like the "display blinking" behavior since PGG had been used asynchronous process instead of synchronous process. As he said, this was not a real problem. Ok. Second, (1) causes a problem which forbids using ISO-8859-1 characters in passphrases. So he proposed (2), but it was not a correct fix (passphrases should be encoded in locale-coding-system rather than just making them unibyte) and it was not working before the reversion. I think this is not so important problem, since it can be avoided by using ASCII only passphrases in practice. Are you saying this problem does not occur if his change (1) is removed? If so, we don't need to solve it, since we have removed (1).