On Fri, Mar 16, 2012 at 5:02 PM, Jim Straus <[email protected]> wrote: > I would like to propose that we can get the equivalent of a packaged web-app > without actually packaging all the content.
due to the security risks, my view is: i strongly suggest that such be only possible if the device is deliberately put into say "developer mode", where all bets are off and the user is really really REALLY clearly advised of such. but... you know what? it's really not that hard to run the "dpkg-buildpackage" command... :) anyway: once you've added a list of URLs to the manifest and a digital signature / checksum on the manifest, you have *exactly* the same concept which is provided "for free" by apt and yum. so.... why bother going to all the trouble of reinventing the wheel? i mean, fine, yes, sure, go ahead - but you'll be at it for... how long? has the B2G team got nothing better to do with its time than to reinvent a 2-decade-long tested and proven package deployment system? :) l. _______________________________________________ dev-security mailing list [email protected] https://lists.mozilla.org/listinfo/dev-security
