Re: [Gimp-web] [Gimp-developer] WGO Update Status

2015-10-07 Thread Dustin Hess
I second https://letsencrypt.org/

It's a free and open product, that's exactly what we need, and the new
website probably won't be live before they are at general availability
anyways.

On Mon, Oct 5, 2015 at 11:59 PM, Owen Cook  wrote:

>
> >
> > I'm close. Today, I finished porting the old tutorials all to the new
> > infrastructure, and I _think_ I've finished porting old pages over.
> >
> > For reference, the list of old URL's for the site can be found on this
> > page: http://static.gimp.org/about/meta/file-list.html
> >
> > The actual list will be linked at the end.
> >
> > Can anyone please take a moment to eyeball the list and provide any
> > feedback?
> >
> > I am also soliciting any feedback in general on the site (
> > http://static.gimp.org). I incorporated some of the changes that jimmac
> > suggested, and am still looking for input/suggestions on things like the
> > verbiage on the new front page, as well as anywhere else.
>
>
>
> I think you have done a tremendous job and don't feel qualified to
> contribute.
>
> The Digital black and white conversion tutorial was excellent. My only
> comment would be to up the copyright notice to 2001-2015
>
> Owen
>
>
> ___
> gimp-web-list mailing list
> gimp-web-list@gnome.org
> https://mail.gnome.org/mailman/listinfo/gimp-web-list
>
___
gimp-web-list mailing list
gimp-web-list@gnome.org
https://mail.gnome.org/mailman/listinfo/gimp-web-list


Re: [Gimp-web] [Gimp-developer] WGO Update Status

2015-10-07 Thread Americo Gobbo
Hi,
I've began now read some of these old posts... are very interesting and
they are put an interesting light in the application name question... many
times I did read in this mailing list discussions very interesting about
this issue.
My suggestion is to create some anchored links from the 'introduction.html'
or a bracket, e.g. [to know more about GIMP acronym] to the the
'ancient_history.html' where was decided the name.

On Mon, Oct 5, 2015 at 5:32 PM, Pat David  wrote:

> http://www.gimp.org/about/ancient_history.html
> 
>
> http://www.gimp.org/about/introduction.html
> 
___
gimp-web-list mailing list
gimp-web-list@gnome.org
https://mail.gnome.org/mailman/listinfo/gimp-web-list


Re: [Gimp-web] [Gimp-developer] WGO Update Status

2015-10-07 Thread Owen Cook

>
> I'm close. Today, I finished porting the old tutorials all to the new
> infrastructure, and I _think_ I've finished porting old pages over.
> 
> For reference, the list of old URL's for the site can be found on this
> page: http://static.gimp.org/about/meta/file-list.html
> 
> The actual list will be linked at the end.
> 
> Can anyone please take a moment to eyeball the list and provide any
> feedback?
> 
> I am also soliciting any feedback in general on the site (
> http://static.gimp.org). I incorporated some of the changes that jimmac
> suggested, and am still looking for input/suggestions on things like the
> verbiage on the new front page, as well as anywhere else.



I think you have done a tremendous job and don't feel qualified to contribute.

The Digital black and white conversion tutorial was excellent. My only comment 
would be to up the copyright notice to 2001-2015

Owen


___
gimp-web-list mailing list
gimp-web-list@gnome.org
https://mail.gnome.org/mailman/listinfo/gimp-web-list


Re: [Gimp-web] [Gimp-developer] WGO Update Status

2015-10-07 Thread Jehan Pagès
Hi,

On Tue, Oct 6, 2015 at 4:52 PM, Pat David  wrote:
> Awesome feedback!  (I thrive on having a task list in front of me!) :D
>
> On Mon, Oct 5, 2015 at 8:38 PM Jehan Pagès 
> wrote:
>>
>> Hi,
>>
>> 1/ Is it possible to force the download page at least to be https?
>> There are some companies which provides free certificates with root CA
>> in all mainstream browsers.
>>
>> This would be a prerequisite to pretend to provide safe download. For
>> instance I see the page provides checksums, which is good but is half
>> meaningless if not provided through a secure channel like https (half
>> because it still allows download corruption check, but not malevolent
>> corruption integrity check).
>
>
> I agree, but this is not a thing that I can do personally.  I'd refer to the
> big gimper, schumaml to find out what the best course of action might be
> here?  Not sure who best to obtain a cert through for our use.  If we do get

The most common CA giving free certs is startSSL: http://www.startssl.com/
The free certs are 1-year and no-wildcards only. But I'm thinking they
may offer help for a project such as GIMP and could provide some certs
with advanced features if we contact them.

Other than this, there is Let's Encrypt (https://letsencrypt.org/), a
project driven by Mozilla among other entities, which aims at
providing free certs for everyone. But their root certs are not yet in
any browser. Right now this is still in "test" state, thus not usable
by gimp.org. Yet we may keep an eye there.

> one, then it would make more sense to simply use it across the entire site
> when we implement.

Yes of course, it would be good to have it everywhere. But this may
not be mandatory everywhere. But for the download page, it has to, in
my opinion. In other words, going to http://static.gimp.org/downloads/
should be impossible and automatically redirect to
https://static.gimp.org/downloads/
This is a basic security mesure. If we allow access to a non-encrypted
version of the download page, this is like a house with a steel
security door and a wood broken door: malevolent people can still use
the wood broken door and the other door is as good as decoration. In
software terms, malevolent people can just do man-in-the-middle
attacks on the non-https page.

But yeah making https mandatory everywhere is even better and very
easy to do (that's a web server configuration).

Jehan

>>
>> 2/ Also still in the download page, could the download links for OS
>> which have any (Windows and OSX) be made into colorful buttons? I
>> believe this simplifies the download task.
>
>
> Yes, absolutely.  Now that the porting is mostly done, I can start focusing
> on styling elements of the page like the download links (they are cute
> buttons on the current WGO, I'll aim for something in a similar vein for
> SGO.
>
>>
>>
>> 3/ If the exact Linux distribution (Fedora rightfully detected, for
>> instance in my case) has been detected, it would be good to have the
>> install information for this distrib at the top (and maybe even the
>> others hidden, unless clicking a "see all Linux distribution" link).
>
>
> I think this is a good idea as well, and will look into expanding the
> detection/show logic to capture more specific instances like this.
>
>>
>>
>> 4/ As sad as it is (for someone like me whose first distribution was
>> Mandrake, later known as Mandriva), the Mandriva company has closed
>> this year. The website has been down for many weeks, thus even though
>> it has been saved many times in the last years, it seems that this
>> time, it is really the end. You may as well remove it from the list.
>>
>>
>> 5/ I propose to add Mageia (which is a community fork of Mandriva,
>> born a few years ago) instead. Same install command as Mandriva.
>
>
> I'm not sure if we want to remove mention of Mandriva completely for
> historical reasons?  (I'm genuinely not sure - my first gut instinct is to
> remove it for the reasons you've listed, and replace it with the Mageia
> reference.  If anyone has a different thought let me know - otherwise I'm
> going with your suggestion).
>
>>
>>
>> 6/ For Fedora, yum is dead. The right install command is: "dnf install
>> gimp" (well yum will still work but will output a deprecation warning
>> and redirect to dnf). Of course, you may provide both commands if you
>> want to be as backward compatible as possible.
>
>
> Thank you, I'll update accordingly!
>
>>
>>
>> 7/ Mint is quite well spread too. I propose to add it to the "Ubuntu,
>> Debian" list. (Mint is mostly derived from Ubuntu, except for one
>> version derived from Debian)
>
>
> I agree, and will add it to the list!  Thank you so much for taking the time
> to have a look and provide detailed feedback!
___
gimp-web-list mailing list
gimp-web-list@gnome.org
https://mail.gnome.org/mailman/listinfo/gimp-web-list


Re: [Gimp-web] [Gimp-developer] WGO Update Status

2015-10-06 Thread Pat David
Awesome feedback!  (I thrive on having a task list in front of me!) :D

On Mon, Oct 5, 2015 at 8:38 PM Jehan Pagès 
wrote:

> Hi,
>
> 1/ Is it possible to force the download page at least to be https?
> There are some companies which provides free certificates with root CA
> in all mainstream browsers.
>
> This would be a prerequisite to pretend to provide safe download. For
> instance I see the page provides checksums, which is good but is half
> meaningless if not provided through a secure channel like https (half
> because it still allows download corruption check, but not malevolent
> corruption integrity check).
>

I agree, but this is not a thing that I can do personally.  I'd refer to
the big gimper, schumaml to find out what the best course of action might
be here?  Not sure who best to obtain a cert through for our use.  If we do
get one, then it would make more sense to simply use it across the entire
site when we implement.


>
> 2/ Also still in the download page, could the download links for OS
> which have any (Windows and OSX) be made into colorful buttons? I
> believe this simplifies the download task.
>

Yes, absolutely.  Now that the porting is mostly done, I can start focusing
on styling elements of the page like the download links (they are cute
buttons on the current WGO, I'll aim for something in a similar vein for
SGO.


>
> 3/ If the exact Linux distribution (Fedora rightfully detected, for
> instance in my case) has been detected, it would be good to have the
> install information for this distrib at the top (and maybe even the
> others hidden, unless clicking a "see all Linux distribution" link).
>

I think this is a good idea as well, and will look into expanding the
detection/show logic to capture more specific instances like this.


>
> 4/ As sad as it is (for someone like me whose first distribution was
> Mandrake, later known as Mandriva), the Mandriva company has closed
> this year. The website has been down for many weeks, thus even though
> it has been saved many times in the last years, it seems that this
> time, it is really the end. You may as well remove it from the list.
>

> 5/ I propose to add Mageia (which is a community fork of Mandriva,
> born a few years ago) instead. Same install command as Mandriva.
>

I'm not sure if we want to remove mention of Mandriva completely for
historical reasons?  (I'm genuinely not sure - my first gut instinct is to
remove it for the reasons you've listed, and replace it with the Mageia
reference.  If anyone has a different thought let me know - otherwise I'm
going with your suggestion).


>
> 6/ For Fedora, yum is dead. The right install command is: "dnf install
> gimp" (well yum will still work but will output a deprecation warning
> and redirect to dnf). Of course, you may provide both commands if you
> want to be as backward compatible as possible.
>

Thank you, I'll update accordingly!


>
> 7/ Mint is quite well spread too. I propose to add it to the "Ubuntu,
> Debian" list. (Mint is mostly derived from Ubuntu, except for one
> version derived from Debian)
>

I agree, and will add it to the list!  Thank you so much for taking the
time to have a look and provide detailed feedback!
___
gimp-web-list mailing list
gimp-web-list@gnome.org
https://mail.gnome.org/mailman/listinfo/gimp-web-list