Gentoo Archives: gentoo-dev

From: Chris Bainbridge <c.j.bainbridge@×××××.uk>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Redux: 2004.1 will not include a secure portage.
Date: Thu, 25 Mar 2004 19:55:26
Message-Id: 200403251955.19000.c.j.bainbridge@ed.ac.uk
In Reply to: Re: [gentoo-dev] Redux: 2004.1 will not include a secure portage. by Jon Portnoy
1 On Thursday 25 March 2004 19:22, Jon Portnoy wrote:
2 > The difference is that we (the developers) control our machines.
3
4 Given that its possible to become a developer without any certification
5 process other than being able to fix a few bugs and use irc; who is really in
6 control?
7
8 * Become a dev
9 * Upload trojan ebuild to randomly corrupt hd then rm -rf / after 24 hours
10 * Cackle as tens of thousands of systems are destroyed
11
12 Is it really that simple? And to fix it is so easy.. just keep a list of
13 people allowed to modify each directory. Developers sign, users check.
14
15 I can't really understand this thread of conversation..
16
17 "Hey, heres a way of solving some security problems"
18 "We're not interested in solving all of those problems at the moment, just one
19 of them"
20 "But you can fix the whole system, and its not difficult"
21 "Not interested. We only want to fix one problem for now."
22
23 --
24 gentoo-dev@g.o mailing list

Replies