[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: CVS
I understand. I didn't mean to start a holy war of any kind here :). But
I agree entirely with Aaron's answer to Dan's question - this is a closed
alpha development. As far as I'm concerned, dev will always be closed to
developers, tst will always be public beta, and www will always be
production quality stuff.
Aaron answerd one of my questions. I just don't want it to be a
requirment in the future for a developer to have a shell account. I think
thats ludicrous to state as a requirment. More shells = less security.
But, Aaron points out the possibility of making it a web-based cgi script,
so they could force the update through a browser, thus removing the shell
requimenr, which is fine.
You also answered why bother doing ssh cvs. Thats fine too, but can we
tunnel cvs over ssh without a shell account? If so great, otherwise
tunneling cvs over ssh should not ever be a requirment either.
Leme know yur thoughts everyone.
Thanks,
Jason
On Sat, Oct 30, 1999 at 06:53:08PM -0700, Aaron Turner wrote:
>
> On Sat, 30 Oct 1999, Daniel E. Markle wrote:
>
> > On Sat, Oct 30, 1999 at 09:26:33AM -0400, Jason Pincin wrote:
> > > Huh? Why does cvs need to be ssh? This is going to be open source
> > > code... why the great security lengths?
> >
>
> Hmmm... let's see:
>
> "Joe Killjoy" decides to have some fun and downloads our CVS tree and
> makes some "minor" changes to things. He can even figure out our
> usernames by our posts on the linuxkb-discuss list which his archived on
> SEUL and pose as us, which would make it very difficult to figure out what
> are legit mods and what aren't.
>
> I don't have any problem with posting our code on a web site or letting
> the world have access to the webcgi interface or anon r/o CVS access.
> But the momement you let anyone have write access to the code you've got a
> major risk. I'd like to see it over ssh, just because I know some of us
> come from high-sniffed environments (college networks and such).
>
> If we don't want to bother with shell access to run webupdate, it would be
> pretty simple to write a CGI program that does it.
>
> > I've been wondering this all along, like why password protect devel?
>
> The theory was that we may have information in IRC logs or email that we
> may not want as public knowledge.
>
> > Why password protect dev?
>
> Because we're doing a closed alpha development? Perhaps tst will be an
> open beta... This is really only a matter of preference on our part. If
> people want an unprotected site, then we should just announce to the world
> an open test.
>
> > If this is your thought on it, we should get rid of
> > these annoying and unproductive checks on these parts of the site.
>
> I guess it's pretty relative. For me, passwords are a way of life. I've
> got so many that I have to store them on my Palm Pilot to keep track. :-)
--
Jason
http://vodka.linuxkb.org/~chardros
- Follow-Ups:
- Re: CVS
- From: Aaron Turner <aturner@linuxkb.org>
- References:
- Re: CVS
- From: "Daniel E. Markle" <syntax@ashtech.net>
- Re: CVS
- From: Aaron Turner <aturner@linuxkb.org>