>>>>> On Wed, 02 Aug 2000 08:19:29 -0700, Jeremy Wadsack <[EMAIL PROTECTED]> 
>said:

 > This sounds as confusing as P3P! Why complicate CPAN? Initializing
 > the CPAN module is already compicted enough for non-Perl users.
 > Certainly some options can have defaults, but what kind of default
 > do you choose for a security measure?

The default is open house of course as is now. Security is a choice
and what I describe here is just what I believe is needed to provide
security for those who want it. I'd welcome soggestions how to make it
easy to use. But befiore we can make it really easy we must have a
working prototype.

>> A signature by PAUSE is an interesting idea. But it would tell the
>> user something different than a signature by a person. While I imagine
>> that a sig by GBARR would mean something like: "I have written or at
>> least doublechecked the code in this package to be free from malicious
>> intent. This is not a warranty." (careful considerations about wording
>> pending). A signature of the PAUSE could only mean "These checksums
>> were valid at the time of the upload."

 > Again, my problem with requiring user signatures is that it
 > complicates the module distribution process. Unless there's a
 > really EASY way for people to acquire a signature and apply it to
 > their modules, you're going to just increase the attrition in Perl
 > developers.

It must be an option item for both producers and consumers, otherwise
it will do what you say. Did I not make it clear enough that I want
security as an optional feature? The OSD should help to implement the
framework that allows security. Currently the options we have are all
too complicated. Please correct me if I'm wrong.

-- 
andreas

Reply via email to