Re: CVS Account Request

From: Date: Wed, 15 Nov 2000 22:15:42 +0000
Subject: Re: CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38227@lists.php.net to get a copy of this message
At 11:03 PM 11/15/2000 +0100, André Langhorst wrote:
Let's not raise the barrier of entry without cause. Show me viable cause and we can talk about specifics. I do agree that Pear needs to be split away at some point when it is mature enough to split. And applying some ACL's to separate doc, web and src code probably makes sense as well. But let's not take this further and start changing something that has worked very well for many years.
I think this is the most reasonable point to start... doc,web,src[,pear] Anyway, if someone was really evil, he could gain trust and cvs access somehow (using current rules or wait-a-few-weeks rule), sure it'll take some time but I don't think this is efficiently preventable until accidently detected.
Or he could do a myriad of other things to find exploits and create bugs, security all relies on human laziness. If your a car thief what car are you going to steal (if their the same model, etc) a car with the door open, the keys in it and the owner on a plane to Italy or a car with the doors closed and locked with the keys safely stowed away. Sure its possible to break into both, but which would you choose? Its the same with PHP, sure there is always going to be a way to introduce bugs, and hurt php, but I could make a commit to phpweb that could have index.php say "Use ASP not PHP" and people probably wouldn't notice until it made the slashdot (ok, a little sooner, but I'm sure it would be there for long enough for someone to notice). In another sense, the same could happen to the source of PHP, but this wouldn't be caught until someone gets bitten by it (and PHP's reputation gets tarnished with a lot of people). -Sterling

« previous php.dev (#38227) next »