Re: Integrity of Apache source code

2007-12-21 Thread Paul Querna
Nikolas Coukouma wrote: Ian Holsman wrote: While open source is fantastic, and provides highly visible means. It can still be hacked. I can describe what has happened in this case: 1. joe hacker hacks one of the 'open source groups' machines. at this point he is assumed to have access to

Re: Integrity of Apache source code

2007-12-20 Thread Ian Holsman
While open source is fantastic, and provides highly visible means. It can still be hacked. I can describe what has happened in this case: 1. joe hacker hacks one of the 'open source groups' machines. at this point he is assumed to have access to the source code repository. 2. assume he

Re: Integrity of Apache source code

2007-12-20 Thread Guy Ferraiolo
One point to consider is that if you are concerned about this you can audit any changes. Guy On Thu, 2007-12-20 at 16:49 -0500, Ian Holsman wrote: While open source is fantastic, and provides highly visible means. It can still be hacked. I can describe what has happened in this case: 1.

Re: Integrity of Apache source code

2007-12-20 Thread Nikolas Coukouma
Ian Holsman wrote: While open source is fantastic, and provides highly visible means. It can still be hacked. I can describe what has happened in this case: 1. joe hacker hacks one of the 'open source groups' machines. at this point he is assumed to have access to the source code

Re: Integrity of Apache source code

2007-12-18 Thread Graham Leggett
Andrew Beverley wrote: I am currently working within the UK Ministry of Defence, and am trying to get Apache web server accredited as software able to be installed on one of our defence networks. However, one of the barriers I am coming up against is the argument that, because it is open

Re: Integrity of Apache source code

2007-12-18 Thread Jim Jagielski
On Dec 17, 2007, at 6:22 PM, Andrew Beverley wrote: Hi, I hope that this is the correct mailing list for this question, and that you can easily provide a quick response. I am currently working within the UK Ministry of Defence, and am trying to get Apache web server accredited as

Integrity of Apache source code

2007-12-17 Thread Andrew Beverley
Hi, I hope that this is the correct mailing list for this question, and that you can easily provide a quick response. I am currently working within the UK Ministry of Defence, and am trying to get Apache web server accredited as software able to be installed on one of our defence networks.

Re: Integrity of Apache source code

2007-12-17 Thread Paul Querna
Andrew Beverley wrote: Hi, I hope that this is the correct mailing list for this question, and that you can easily provide a quick response. I am currently working within the UK Ministry of Defence, and am trying to get Apache web server accredited as software able to be installed on one of

Re: Integrity of Apache source code

2007-12-17 Thread Nick Kew
On Mon, 17 Dec 2007 23:22:37 + Andrew Beverley [EMAIL PROTECTED] wrote: Hi, I hope that this is the correct mailing list for this question, and that you can easily provide a quick response. Not quickly, beyond what's on the apache webpages, or published elsewhere (e.g. Chapter 1 of my

Re: Integrity of Apache source code

2007-12-17 Thread Colm MacCarthaigh
On Mon, Dec 17, 2007 at 11:22:37PM +, Andrew Beverley wrote: I am currently working within the UK Ministry of Defence, and am trying to get Apache web server accredited as software able to be installed on one of our defence networks. However, one of the barriers I am coming up against is

Re: Integrity of Apache source code

2007-12-17 Thread Sander Temme
Andrew, On Dec 17, 2007, at 3:22 PM, Andrew Beverley wrote: What I would like to know, so that I can dispel this, is what procedures are in place to prevent this happening? I know that all downloads are digitally signed, but what other procedures are in place? For example, how is code

Re: Integrity of Apache source code

2007-12-17 Thread Davi Arnaut
Andrew Beverley wrote: Hi, I hope that this is the correct mailing list for this question, and that you can easily provide a quick response. I am currently working within the UK Ministry of Defence, and am trying to get Apache web server accredited as software able to be installed on