On Wed, 14 Mar 2007 22:56:31 +0100 Paul de Vrieze <[EMAIL PROTECTED]>
wrote:
> On Wednesday 14 March 2007, Stephen Bennett wrote:
> > On Wed, 14 Mar 2007 16:38:20 +0100
> >
> > "Ioannis Aslanidis" <[EMAIL PROTECTED]> wrote:
> > > Ciaran, honestly and without any offense intention, what would be
> > > your answers to the questions you formulated? If you ask all
> > > that, assuming it's all rethoric, what is your opinion?
> >
> > I think his intention was to demonstrate that the idea is
> > implausible, at best counterproductive and at worst disastrous.
> > Which it is, and which he did fairly well.
> 
> Could you explain how this is implausible. Removing contributions by
> a certain person may be silly or impossible. Refusing to accept new
> contributions is, while a very harsh measure, a possibility.

Right up until the point where it leads to data loss, security holes or
the inability to use important packages...

What do you think users will say when told that their system will
remain vulnerable to a remote root hole because Gentoo won't accept a
fix from a particular person? Do you think they'll smile, nod and
accept that their system is about to get taken over by some kid in
Russia, or do you think they'll scream and switch to Ubuntu?

Heck, that this even has to be spelt out is pretty scary...

(Bear in mind that claiming to have independently rediscovered a hole
and indepedently recreated a two line security change is not exactly
going to go over well either...)

-- 
Ciaran McCreesh
Mail                                : ciaranm at ciaranm.org
Web                                 : http://ciaranm.org/
Paludis, the secure package manager : http://paludis.pioto.org/

Attachment: signature.asc
Description: PGP signature

Reply via email to