Re: bug#68687: Org mode code evaluation (was: bug#68687: [PATCH] Use text/org media type)

2024-02-02 Thread Ihor Radchenko
[ dropping debbugs from the loop ] Richard Stallman writes: > > I did not imply that Org mode is safe. I directly said that there are > > security issues and that they are known. > > Could you plesae post a pointer to a desciption of them? https://list.orgmode.org/orgmode/u2qqki$25r$1...@ci

Re: bug#68687: Org mode code evaluation (was: bug#68687: [PATCH] Use text/org media type)

2024-02-01 Thread Richard Stallman
[[[ To any NSA and FBI agents reading my email: please consider]]] [[[ whether defending the US Constitution against all enemies, ]]] [[[ foreign or domestic, requires you to follow Snowden's example. ]]] > I did not imply that Org mode is safe. I directly said that there are > securit

Org mode code evaluation (was: bug#68687: [PATCH] Use text/org media type)

2024-01-31 Thread Mike Kupfer
Ihor Radchenko wrote: > Max is referring to various security issues with evaluating code inside > Org mode buffers. They are known, but not relevant to Org text being > displayed in email MUA - Org never evaluates any code automatically > without user explicitly asking for it. And in MUA, Org mode

Re: Org mode code evaluation (was: bug#68687: [PATCH] Use text/org media type)

2024-01-30 Thread Ihor Radchenko
Mike Kupfer writes: > I can believe that Org text snippets are safe in an email MUA. That's exactly what I wanted to emphasize. > But in the general case, I don't think Org mode is quite as safe as you > implied. I did not imply that Org mode is safe. I directly said that there are security