RE: [PHP-DEV] CVS Account Request

From: Date: Wed, 15 Nov 2000 22:42:33 +0000
Subject: RE: [PHP-DEV] CVS Account Request
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-38245@lists.php.net to get a copy of this message
At 01:33 16/11/2000, Rasmus Lerdorf wrote:
You can't tell for sure. For all you know, you could argue that I (Zeev) might be an undercover Bin Laden agent, in one of the most successful undercover missions in history, trying to bring down the entire imperialistic American web. Possible, but unlikely. I dunno, I have often suspected that to be true.
I'm sure you did :)
I gather that someone committing legitimate patches may still be a hacker, but the likelihood goes down, significantly. And if he is sending us good patches to gain trust, great. Once he sends the nasty patch, even if it takes us a little while to catch it, we can roll back the bad ones and keep the good ones and in the end we are ahead.
You are assuming, again, that you'd notice the bad patch. You most probably won't, so you should reduce the likelihood of this bad patch coming in in the first place. It's true that allowing access only to people that actually 'prove' themselves doesn't make things bulletproof, far from it. But is it better than not doing it at all? Definitely yes. Security (and safety) are relative terms, they're never absolute. Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/

« previous php.dev (#38245) next »