emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: gmail+imap+smtp (oauth2)


From: Tim Cross
Subject: Re: gmail+imap+smtp (oauth2)
Date: Fri, 06 May 2022 23:05:17 +1000
User-agent: mu4e 1.7.13; emacs 28.1.50

Stefan Monnier <monnier@iro.umontreal.ca> writes:

>> We know.  They know.  We know they know.  They know we know they know.
>> We've been down this drm-keys-embedded-in-application tango so many
>> times already-
>>
>> Now someone explain to me: why do they nevertheless do it?
>
> Regardless of this "why", I think what it means is that it's perfectly
> OK to use it in Free Software, with the "secret" key in plain sight.
>
> I think from Google's point of view all it means is that we're more
> prone to DoS attacks where someone abuses the "secret" key causing
> Google to revoke the key.  Google won't suffer from it, we will, so they
> don't care.
>

Agree. I also suspect this is the same rationale being used by
Thunderbird and others. 




reply via email to

[Prev in Thread] Current Thread [Next in Thread]