emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: security of the emacs package system, elpa, melpa and marmalade


From: Stefan Monnier
Subject: Re: security of the emacs package system, elpa, melpa and marmalade
Date: Wed, 25 Sep 2013 21:09:42 -0400
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3.50 (gnu/linux)

> The question that is bugging me now: Why is that?

For the same reason it uses dynamic scoping, dynamic typing, hooks
galore, defadvice, ...
Emacs is about empowering the user.

Also it grew in a context where security was not a serious concern.

> I'm just throwing my thoughts in the mix at this time.  All this would
> need a lot more thought and work, obviously. But I honestly think this
> would be a goal worth pursuing since security should never be taken
> lightly, imho.

To me, the problem it too ill-understood to be able to design a workable
solution.  So I think the only way to attack the problem is to
perform experiments to get a feel for what might work and what problems
show up.


        Stefan



reply via email to

[Prev in Thread] Current Thread [Next in Thread]