[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: CVS
On Sat, 30 Oct 1999, Daniel E. Markle wrote:
> On Sat, Oct 30, 1999 at 09:26:33AM -0400, Jason Pincin wrote:
> > Huh? Why does cvs need to be ssh? This is going to be open source
> > code... why the great security lengths?
>
Hmmm... let's see:
"Joe Killjoy" decides to have some fun and downloads our CVS tree and
makes some "minor" changes to things. He can even figure out our
usernames by our posts on the linuxkb-discuss list which his archived on
SEUL and pose as us, which would make it very difficult to figure out what
are legit mods and what aren't.
I don't have any problem with posting our code on a web site or letting
the world have access to the webcgi interface or anon r/o CVS access.
But the momement you let anyone have write access to the code you've got a
major risk. I'd like to see it over ssh, just because I know some of us
come from high-sniffed environments (college networks and such).
If we don't want to bother with shell access to run webupdate, it would be
pretty simple to write a CGI program that does it.
> I've been wondering this all along, like why password protect devel?
The theory was that we may have information in IRC logs or email that we
may not want as public knowledge.
> Why password protect dev?
Because we're doing a closed alpha development? Perhaps tst will be an
open beta... This is really only a matter of preference on our part. If
people want an unprotected site, then we should just announce to the world
an open test.
> If this is your thought on it, we should get rid of
> these annoying and unproductive checks on these parts of the site.
I guess it's pretty relative. For me, passwords are a way of life. I've
got so many that I have to store them on my Palm Pilot to keep track. :-)
- Follow-Ups:
- Re: CVS
- From: Jason Pincin <chardros@linuxkb.org>
- References:
- Re: CVS
- From: "Daniel E. Markle" <syntax@ashtech.net>