Gentoo Archives: gentoo-dev

From: Chris Gianelloni <wolf31o2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Project Sunrise thread -- a try of clarification
Date: Thu, 08 Jun 2006 22:29:19
Message-Id: 1149804878.19443.114.camel@cgianelloni.nuvox.net
In Reply to: Re: [gentoo-dev] Project Sunrise thread -- a try of clarification by Ciaran McCreesh
1 On Thu, 2006-06-08 at 21:35 +0100, Ciaran McCreesh wrote:
2 > On Thu, 08 Jun 2006 23:52:50 +0400 "Peter Volkov (pva)"
3 > <pva@g.o> wrote:
4 > | > Will you also review the code each and every ebuild pull down over
5 > | > the internet?
6 > |
7 > | And that is really exciting moment. :) The main difference between
8 > | such overlay and wiki is that reading text never does `rm -rf /`. How
9 > | can one stop such jokes? I think if this problem will be solved such
10 > | overlay should be.
11 >
12 > Somehow I think certain people aren't quite grasping the potential
13 > security breaches with this whole thing... Slipping in malicious and
14 > hard to detect code that gets executed by everybody is very very easy.
15
16 You mean like:
17
18 perl -e 'print
19 i=pack(c5,(41*2),sqrt(7056),(unpack(c,H)-2),oct(115),10);'
20
21 I'm sure everyone will get what that means in a quick cursory glance...
22 and of course repoman will know what it does, right?
23
24 *grin*
25
26 --
27 Chris Gianelloni
28 Release Engineering - Strategic Lead
29 x86 Architecture Team
30 Games - Developer
31 Gentoo Linux

Attachments

File name MIME type
signature.asc application/pgp-signature