Re: Bitkeeper licence issues

Pavel Machek (pavel@suse.cz)
Tue, 19 Mar 2002 23:06:32 +0100


Hi!

> > > Pavel, the problem here is your fundamental distrust.
> > By giving me binary-only installer you ask me to trust you. You ask me
> > to trust you without good reason [it only generates .tar.gz and
> > shellscript, why should it be binary? Was not shar designed to handle
> > that?], and that's pretty suspect.
>
> Bitmover doing anything remotely suspect in an executable installer
> would be commercial suicide, do you distrust realplayer too?

Actually, the installer contains security hole allowing any user to
overwrite any file on system if you install it as root with simple
symlink. [Its easy to fix, and I hope they fix it in next version.]

Do you see why I hate binary installers, now?
Pavel

-- 
(about SSSCA) "I don't say this lightly.  However, I really think that the U.S.
no longer is classifiable as a democracy, but rather as a plutocracy." --hpa
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/