On 11.08.2008 14:53, Rex Dieter wrote:
Thorsten Leemhuis wrote:
I won't publicly document either when I'm on vacation, so I bite
and jump into this discussion:
Could the "vacation" page be locked down require authenticated access
(ie, no anonymous viewing)? Would that help?
I suppose that page would still be open to all the other packagers? Call
me paranoid, but in that case I don't think that would be much of a help
-- we have hundreds of packagers and it's not that hard to get
sponsored. So a malicious attacker (or a Fedora packager that suddenly
is mad about Fedora and want to do a lot of harm) would not only have
access to all packages that are free for cvsextras/packers group but
also to a list of good targets (e.g. packages from packagers on vacation).
CU
knurd
--
fedora-devel-list mailing list
fedora-devel-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/fedora-devel-list