Date: 11/15/00
- Next message: Sterling Hughes: "RE: [PHP-DEV] CVS Account Request"
- Previous message: André Langhorst: "Re: [PHP-DEV] CVS Account Request"
- Next in thread: André Langhorst: "Re: [PHP-DEV] CVS Account Request"
- Reply: André Langhorst: "Re: [PHP-DEV] CVS Account Request"
- Reply: Mike Robinson: "RE: [PHP-DEV] CVS Account Request"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
At 01:33 16/11/2000, Rasmus Lerdorf wrote:
> > You can't tell for sure. For all you know, you could argue that I (Zeev)
> > might be an undercover Bin Laden agent, in one of the most successful
> > undercover missions in history, trying to bring down the entire
> > imperialistic American web. Possible, but unlikely.
>
>I dunno, I have often suspected that to be true.
I'm sure you did :)
> > I gather that someone committing legitimate patches may still be a hacker,
> > but the likelihood goes down, significantly.
>
>And if he is sending us good patches to gain trust, great. Once he sends
>the nasty patch, even if it takes us a little while to catch it, we can
>roll back the bad ones and keep the good ones and in the end we are ahead.
You are assuming, again, that you'd notice the bad patch. You most
probably won't, so you should reduce the likelihood of this bad patch
coming in in the first place. It's true that allowing access only to
people that actually 'prove' themselves doesn't make things bulletproof,
far from it. But is it better than not doing it at all? Definitely yes.
Security (and safety) are relative terms, they're never absolute.
Zeev
-- Zeev Suraski <zeev <email protected>> CTO, Zend Technologies Ltd. http://www.zend.com/-- PHP Development Mailing List <http://www.php.net/> To unsubscribe, e-mail: php-dev-unsubscribe <email protected> For additional commands, e-mail: php-dev-help <email protected> To contact the list administrators, e-mail: php-list-admin <email protected>
- Next message: Sterling Hughes: "RE: [PHP-DEV] CVS Account Request"
- Previous message: André Langhorst: "Re: [PHP-DEV] CVS Account Request"
- Next in thread: André Langhorst: "Re: [PHP-DEV] CVS Account Request"
- Reply: André Langhorst: "Re: [PHP-DEV] CVS Account Request"
- Reply: Mike Robinson: "RE: [PHP-DEV] CVS Account Request"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

