1 |
On Thu, 2004-03-25 at 14:55, Chris Bainbridge wrote: |
2 |
> On Thursday 25 March 2004 19:22, Jon Portnoy wrote: |
3 |
> > The difference is that we (the developers) control our machines. |
4 |
> |
5 |
> Given that its possible to become a developer without any certification |
6 |
> process other than being able to fix a few bugs and use irc; who is really in |
7 |
> control? |
8 |
|
9 |
We tend to only allow people whom have made valued contributions to |
10 |
Gentoo in the past. We tend to *not* bring on people who seem too eager |
11 |
in gaining developer status. With that being said, yes, there is a VERY |
12 |
large amount of trust put in every Gentoo developer. |
13 |
|
14 |
YOU also agree to that trust simply by installing Gentoo on your |
15 |
machine. |
16 |
|
17 |
> * Become a dev |
18 |
> * Upload trojan ebuild to randomly corrupt hd then rm -rf / after 24 hours |
19 |
> * Cackle as tens of thousands of systems are destroyed |
20 |
> |
21 |
> Is it really that simple? And to fix it is so easy.. just keep a list of |
22 |
> people allowed to modify each directory. Developers sign, users check. |
23 |
|
24 |
It really is that simple. |
25 |
|
26 |
The list would also be pretty simple, since all Gentoo developers have |
27 |
access to the entire tree. |
28 |
|
29 |
> I can't really understand this thread of conversation.. |
30 |
> |
31 |
> "Hey, heres a way of solving some security problems" |
32 |
> "We're not interested in solving all of those problems at the moment, just one |
33 |
> of them" |
34 |
> "But you can fix the whole system, and its not difficult" |
35 |
> "Not interested. We only want to fix one problem for now." |
36 |
|
37 |
I don't understand where these comments are coming from. |
38 |
|
39 |
-- |
40 |
Chris Gianelloni |
41 |
Developer, Gentoo Linux |
42 |
Games Team |
43 |
|
44 |
Is your power animal a pengiun? |