Freenet RCS security

Matthew Toseland <toad-EI5O+8PHWbJeeLb3ft/[email protected]>
Newsgroups gmane.network.freenet.technical,gmane.network.freenet.general
Message-ID <[email protected]>
If somebody compromizes the Subversion (or CVS) repository, they can
potentially do commits without them going to the commit list, and
therefore introduce evil code. Hopefully this will be picked up, but
Freenet is quite large. If you want a non-java task to increase
freenet's security, I suggest a script that can cross-reference the CVS
list emails with the actual log from SVN/CVS, and flags up any
discrepancies. If such a thing already exists, I'd be very interested;
if it does not, some perl hacker who can't be bothered to learn java
could write it.
-- 
Matthew J Toseland - toad-EI5O+8PHWbJeeLb3ft/[email protected]
Freenet Project Official Codemonkey - http://freenetproject.org/
ICTHUS - Nothing is impossible. Our Boss says so.

_______________________________________________
Tech mailing list
[email protected]
http://emu.freenetproject.org/cgi-bin/mailman/listinfo/tech
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.1 (GNU/Linux)

iD8DBQFDSC2+HzsuOmVUoi0RAh2gAKCuInESNMuXbju78T1NJkEZVwrHuwCcCYDJ
kJ4dpnQI0wX5Ch86FMo/ESc=
=Igwh
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.