>>>>> On Wed, 02 Aug 2000 08:19:29 -0700, Jeremy Wadsack <[EMAIL PROTECTED]> >said: > This sounds as confusing as P3P! Why complicate CPAN? Initializing > the CPAN module is already compicted enough for non-Perl users. > Certainly some options can have defaults, but what kind of default > do you choose for a security measure? The default is open house of course as is now. Security is a choice and what I describe here is just what I believe is needed to provide security for those who want it. I'd welcome soggestions how to make it easy to use. But befiore we can make it really easy we must have a working prototype. >> A signature by PAUSE is an interesting idea. But it would tell the >> user something different than a signature by a person. While I imagine >> that a sig by GBARR would mean something like: "I have written or at >> least doublechecked the code in this package to be free from malicious >> intent. This is not a warranty." (careful considerations about wording >> pending). A signature of the PAUSE could only mean "These checksums >> were valid at the time of the upload." > Again, my problem with requiring user signatures is that it > complicates the module distribution process. Unless there's a > really EASY way for people to acquire a signature and apply it to > their modules, you're going to just increase the attrition in Perl > developers. It must be an option item for both producers and consumers, otherwise it will do what you say. Did I not make it clear enough that I want security as an optional feature? The OSD should help to implement the framework that allows security. Currently the options we have are all too complicated. Please correct me if I'm wrong. -- andreas

