Sean Rooney wrote:

> simple, have an independent 3rd party audit/code review done. use three
> teams, take a 2/3rds majority vote on everything.

I wouldn't use a '2/3 majority' here. The smallest stakeholder who finds a
protential problem with code is able to raise alarms.

We want to assure that there is greater pressure to find problems than to be
complacent, and that there is greater pressure to publish problems and fix
code than to keep quiet about it.

The more the largest stakeholders use the product to protect their own
secrets, and the less they trust each other, the more pressure there is for
each to find and fix problems.... but this doesn't pressure them enough to
publish their fixes.


Does anyone here believe the stakeholders are altruistic?

Does anyone here believe the stakeholders do not have enough resources by
themselves to detect and fix holes?

Does anyone here believe the stakeholders are required to alert their allies
to danger by publishing their fixes rather than distributing them privately?

Does anyone here believe the stakeholders can convert their enemies into
allies by publishing?

Does anyone here believe there is no potential for a conspiracy in the works?

--
Paul Shields
[EMAIL PROTECTED]



Reply via email to