From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from lists.gentoo.org ([140.105.134.102] helo=robin.gentoo.org) by nuthatch.gentoo.org with esmtp (Exim 4.60) (envelope-from ) id 1FoRJS-0007Uk-Aa for garchives@archives.gentoo.org; Thu, 08 Jun 2006 20:41:06 +0000 Received: from robin.gentoo.org (localhost [127.0.0.1]) by robin.gentoo.org (8.13.6/8.13.6) with SMTP id k58Kd7dE031703; Thu, 8 Jun 2006 20:39:07 GMT Received: from smtp-out5.blueyonder.co.uk (smtp-out5.blueyonder.co.uk [195.188.213.8]) by robin.gentoo.org (8.13.6/8.13.6) with ESMTP id k58KZmsv028415 for ; Thu, 8 Jun 2006 20:35:49 GMT Received: from [172.23.170.146] (helo=anti-virus03-09) by smtp-out5.blueyonder.co.uk with smtp (Exim 4.52) id 1FoREK-0006og-Jm for gentoo-dev@lists.gentoo.org; Thu, 08 Jun 2006 21:35:48 +0100 Received: from [213.121.151.206] (helo=snowdrop.home) by asmtp-out1.blueyonder.co.uk with esmtpa (Exim 4.52) id 1FoREH-0005oy-0d for gentoo-dev@lists.gentoo.org; Thu, 08 Jun 2006 21:35:45 +0100 Date: Thu, 8 Jun 2006 21:35:07 +0100 From: Ciaran McCreesh To: gentoo-dev@lists.gentoo.org Subject: Re: [gentoo-dev] Project Sunrise thread -- a try of clarification Message-ID: <20060608213507.528a03f2@snowdrop.home> In-Reply-To: <1149796370.16025.21.camel@localhost> References: <44887368.9030302@gentoo.org> <20060608192004.GC6526@osgiliath> <1149796370.16025.21.camel@localhost> X-Mailer: Sylpheed-Claws 2.3.0-rc3 (GTK+ 2.8.18; i686-pc-linux-gnu) Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Linux mail X-BeenThere: gentoo-dev@gentoo.org Reply-to: gentoo-dev@lists.gentoo.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Archives-Salt: 979be0b2-fa62-445b-8646-a983b06a0d04 X-Archives-Hash: 9df65261d790d4a0cf9f64c6d8d91827 On Thu, 08 Jun 2006 23:52:50 +0400 "Peter Volkov (pva)" wrote: | > Will you also review the code each and every ebuild pull down over | > the internet? | | And that is really exciting moment. :) The main difference between | such overlay and wiki is that reading text never does `rm -rf /`. How | can one stop such jokes? I think if this problem will be solved such | overlay should be. Somehow I think certain people aren't quite grasping the potential security breaches with this whole thing... Slipping in malicious and hard to detect code that gets executed by everybody is very very easy. -- Ciaran McCreesh Mail : ciaran dot mccreesh at blueyonder.co.uk -- gentoo-dev@gentoo.org mailing list