emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Rationale for this change?


From: David Kastrup
Subject: Rationale for this change?
Date: Wed, 28 Dec 2005 20:47:17 +0100
User-agent: Gnus/5.11 (Gnus v5.11) Emacs/22.0.50 (gnu/linux)

2005-12-05  Ralf Angeli  <address@hidden>

        * mail/smtpmail.el (smtpmail-try-auth-methods):
        Send credentials together with "AUTH PLAIN" command.

I have not seen this discussed on the list, and it feels to me that
this defeats system administrators who disable "AUTH PLAIN" because
they consider the access path to the mail server under their
administration unsafe for plain text transfers.  While the
authentication is refused, the authentication data itself is still
sent through the network after this change, making the refusal of
"AUTH PLAIN" ineffective for avoiding ill consequences of snoopable
connections.

Could you shed any light on what problem this change is intended to
fix?

-- 
David Kastrup, Kriemhildstr. 15, 44793 Bochum




reply via email to

[Prev in Thread] Current Thread [Next in Thread]