[Sugar-devel] Discrepancy regarding an Activity

Jonas Smedegaard dr at jones.dk
Sun Nov 15 07:47:08 EST 2009


On Sun, Nov 15, 2009 at 02:24:30PM +0530, Mohit Taneja wrote:
>I guess only the copyrights have been changed.

>On Wed, Nov 11, 2009 at 5:23 AM, Deepank Gupta 
><deepankgupta at gmail.com>wrote:
>> They have just changed the name from Foodforce2 to FoodforceII and 
>> also it is just a packaging of revision no 85. No value addition or 
>> anything in it...

>> On Tue, Nov 10, 2009 at 2:31 PM, Himanshu Hind 
>> <cooldude2064 at gmail.com>wrote:
>>> Right now I am running addon 4206 as it has more number of downloads 
>>> and thus seems to be more stable [than addon 4219].


Hmmm - how can one be more stable than the other if no code changed?

Could it be that even if the source is identical the binary packaging 
somehow is different?

...which leads me to a horrible thought: What is the risk of damage if 
someone uploads delibarately evil binary code?

By comparison, Debian have little technical protection against uploading 
evil code, but have a social "mechanism" of only allowing official 
members to upload (combined with requiring a large effort to become 
"official member").  I do not see the Debian design here as brilliant, 
but it seems to me that current Sugarlabs approach is even weaker :-/


Kind regards,

  - Jonas

-- 
* Jonas Smedegaard - idealist & Internet-arkitekt
* Tlf.: +45 40843136  Website: http://dr.jones.dk/

  [x] quote me freely  [ ] ask before reusing  [ ] keep private
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 836 bytes
Desc: Digital signature
Url : http://lists.sugarlabs.org/archive/sugar-devel/attachments/20091115/d7d23eb4/attachment.pgp 


More information about the Sugar-devel mailing list