Gentoo Archives: gentoo-dev

From: Chris Gianelloni <wolf31o2@g.o>
To: Chris Bainbridge <c.j.bainbridge@×××××.uk>
Cc: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Redux: 2004.1 will not include a secure portage.
Date: Thu, 25 Mar 2004 20:32:18
Message-Id: 1080246712.12031.12.camel@localhost
In Reply to: Re: [gentoo-dev] Redux: 2004.1 will not include a secure portage. by Chris Bainbridge
1 On Thu, 2004-03-25 at 14:55, Chris Bainbridge wrote:
2 > On Thursday 25 March 2004 19:22, Jon Portnoy wrote:
3 > > The difference is that we (the developers) control our machines.
4 >
5 > Given that its possible to become a developer without any certification
6 > process other than being able to fix a few bugs and use irc; who is really in
7 > control?
8
9 We tend to only allow people whom have made valued contributions to
10 Gentoo in the past. We tend to *not* bring on people who seem too eager
11 in gaining developer status. With that being said, yes, there is a VERY
12 large amount of trust put in every Gentoo developer.
13
14 YOU also agree to that trust simply by installing Gentoo on your
15 machine.
16
17 > * Become a dev
18 > * Upload trojan ebuild to randomly corrupt hd then rm -rf / after 24 hours
19 > * Cackle as tens of thousands of systems are destroyed
20 >
21 > Is it really that simple? And to fix it is so easy.. just keep a list of
22 > people allowed to modify each directory. Developers sign, users check.
23
24 It really is that simple.
25
26 The list would also be pretty simple, since all Gentoo developers have
27 access to the entire tree.
28
29 > I can't really understand this thread of conversation..
30 >
31 > "Hey, heres a way of solving some security problems"
32 > "We're not interested in solving all of those problems at the moment, just one
33 > of them"
34 > "But you can fix the whole system, and its not difficult"
35 > "Not interested. We only want to fix one problem for now."
36
37 I don't understand where these comments are coming from.
38
39 --
40 Chris Gianelloni
41 Developer, Gentoo Linux
42 Games Team
43
44 Is your power animal a pengiun?

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] Redux: 2004.1 will not include a secure portage. Paul de Vrieze <pauldv@g.o>