[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Public guix offload server
From: |
zimoun |
Subject: |
Re: Public guix offload server |
Date: |
Thu, 21 Oct 2021 23:51:25 +0200 |
Hi,
On Thu, 21 Oct 2021 at 21:15, "Jonathan McHugh" <indieterminacy@libre.brussels>
wrote:
> October 21, 2021 8:10 PM, "zimoun" <zimon.toutoune@gmail.com> wrote:
>>> Now, we could spin up a separate VM for each user, and just take
>>> the efficiency hit… Users would be safe from anything but
>>> VM-escape exploits (which exist but are rare).
>>
>> Do you mean that trusted users would try WM-escape exploits?
>
> The world has been formed by warewolves inside communities purposely
> causing harm. Looking further back, Oliver the Spy is a classic
> examplar of trust networks being hollowed out.
I cannot assume that on one hand one trusted person pushes to the main
Git repo in good faith and on other hand this very same trusted person
behaves as a warewolves using a shared resource.
For sure, one can always abuse the trust. Based on this principle, we
could stop any collaborative work right now. The real question is the
evaluation of the risk of such abuse by trusted people after long period
of collaboration (that’s what committer usually means).
Various examples exist on this kind of abused trust. Oliver the Spy is
one, Mark Kennedy/Stone is another recent one.
Anyway! :-)
All the best,
simon
- Public guix offload server, Arun Isaac, 2021/10/20
- Re: Public guix offload server, Tobias Geerinckx-Rice, 2021/10/20
- Re: Public guix offload server, Leo Famulari, 2021/10/20
- Re: Public guix offload server, zimoun, 2021/10/21
- Re: Public guix offload server, Tobias Geerinckx-Rice, 2021/10/21
- Re: Public guix offload server, zimoun, 2021/10/21
- Re: Public guix offload server, Jonathan McHugh, 2021/10/21
- Re: Public guix offload server,
zimoun <=
- Re: Public guix offload server, Tobias Geerinckx-Rice, 2021/10/21
- Re: Public guix offload server, zimoun, 2021/10/22
- Re: Public guix offload server, Arun Isaac, 2021/10/23
- Re: Public guix offload server, zimoun, 2021/10/23
- Re: Public guix offload server, Arun Isaac, 2021/10/24
- Re: Public guix offload server, indieterminacy, 2021/10/25
- Re: Public guix offload server, Jonathan McHugh, 2021/10/22
Re: Public guix offload server, Arun Isaac, 2021/10/21
Re: Public guix offload server, Ludovic Courtès, 2021/10/29