Re: CVS Account Request

From: Date: Wed, 15 Nov 2000 23:01:25 +0000
Subject: Re: CVS Account Request
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-38252@lists.php.net to get a copy of this message
Security (and safety) are relative terms, they're never absolute.
anyway, an improvment over the current situation will be to limit "web" cvs access to as few people as possible to avoid beeing "hacked" and slashdotted afterwards, eg. "surprisingly php releases a new verison - PHP 5 (3xt3nD4d) - featuring warez, porn and building bombs" guessing a private "hacker" does it would not generate any positive effect for PHP I think :) Remembering, 2 month ago, I was *really* surprised when Rasmus told me to make changes to the php website myself, sure - I've had CVS access and sure "phpweb" is in the CVS list, but I wouldn't have thought to have access to the site itself, ok. - perhaps he knew I would not do any harm, but anyone with CVS access could have tried if access is possible editing the "links" section and then shut down the whole site while rasmus is sleeping replacing it with anything else... this should be done as fast as possibe (guessing the enemy is listening ;) ) andré

« previous php.dev (#38252) next »