PackageKit policy: background and plans

Gregory Maxwell gmaxwell at gmail.com
Tue Nov 24 00:01:36 UTC 2009


On Mon, Nov 23, 2009 at 6:43 PM, Jesse Keating <jkeating at j2solutions.net> wrote:
> This is precisely the dialog that has been removed from F12 and is not
> planned to be returned.

My understanding was that this was removed because collecting the root password
during a user session is insecure because there could be a sniffer or the dialog
could be faked.

If I understand you correctly you are saying that even if this weakness were
addressed (e.g. through whatever means make fast user switching secure) that
the feature would not be re-introduced.  Am I misunderstanding?

If I am not misunderstand, can you point me to the real reason that this feature
was removed?

Thanks!




More information about the devel mailing list