httpd installed by default on desktops! bad gnome-user-share, bad!

Matthew Miller mattdm at mattdm.org
Mon Apr 9 16:39:36 UTC 2007


On Mon, Apr 09, 2007 at 11:10:52AM -0500, Jon Ciesla wrote:
> +1.  If the nailgun is unplugged, in the box, and the nails are in a
> separate box, why not ship them?  Provide the functionality, but in a safe
> manner.  Is this not the current state?

a) It's really easy to turn on without recognizing the implications.
b) It's fairly easy to turn on full httpd without recognizing the
   implications.
c) The most secure code is the code that's not on the box.
d) Having a) means that it's more difficult to notice when b) happens.


-- 
Matthew Miller           mattdm at mattdm.org          <http://mattdm.org/>
Boston University Linux      ------>              <http://linux.bu.edu/>




More information about the devel mailing list