RE: [PHP-DEV] CVS Account Request
| From: | Zeev Suraski | Date: | Wed, 15 Nov 2000 23:06:13 +0000 |
| Subject: | RE: [PHP-DEV] CVS Account Request | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-38254@lists.php.net to get a copy of this message | ||
At 20:52 15/11/2000, John Donagher wrote:
The apache hack was a system-level vulnerability which is something any software distribution repository is vulnerable to.It doesn't really matter. I wanted to show that the motivation is there, and the danger of hacking into opensource software repositories exists, and people who say that are not paranoid. They say that generals always prepare for the previous war, we shouldn't make the same mistake and assume that's the only way to hack in.
I tend to agree with Rasmus on this one. Although someone could certainly commit malicious code to the repository, the likelihood of someone relatively unknown (like me) slipping code past the subscribers of php-cvs is probably not an easy thing. I don't think cutting off so many potential contributors at the ankles would be beneficial to PHP's evolution.It's not cutting them in the ankles, it's not even giving them a paper cut. It's nothing serious, and it can help reduce the security problem. Not *solve* it, *reduce* it. Zeev -- Zeev Suraski <zeev@zend.com> CTO, Zend Technologies Ltd. http://www.zend.com/