<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-8108277809937554792.post1163343893600586948..comments</id><updated>2009-11-23T07:50:39.070-06:00</updated><title type='text'>Comments on SteveCo: Why developers suck as admins</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.stevecoinc.com/feeds/1163343893600586948/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html'/><author><name>Steven Pritchard</name><uri>http://www.blogger.com/profile/00716303018104544735</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>4</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-3383828448662250778</id><published>2009-11-23T07:50:39.070-06:00</published><updated>2009-11-23T07:50:39.070-06:00</updated><title type='text'>old timer?! I'm 33!</title><content type='html'>old timer?! I&amp;#39;m 33!</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/3383828448662250778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/3383828448662250778'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html?showComment=1258984239070#c3383828448662250778' title=''/><author><name>skvidal</name><uri>http://www.blogger.com/profile/00993961635850065167</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1163343893600586948' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1163343893600586948' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-555560888818049373</id><published>2009-11-21T15:50:51.385-06:00</published><updated>2009-11-21T15:50:51.385-06:00</updated><title type='text'>Now that I have fully read and study the case, the...</title><content type='html'>Now that I have fully read and study the case, the incident is a classic example of failure of communication. There is not a problem with the functionality. (Credit for GeneralZod from linuxfr.org for detailed information)&lt;br /&gt;&lt;br /&gt;&lt;i&gt;    * The installation of one package shouldn&amp;#39;t change the behavior of the system. (This one package changes the behavior of the system, plus allows for other packages to be installed that could do the same.) If you take into account that unintended dependencies tend to pull in random stuff during upgrades, this becomes especially important.&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;It is actually policies change from Freedesktop discussed on mail list six months ago. The maintainer of PackageKit only applies it and only concerns local users. Note that behaviour only applies for signed packages from trusted repositories  i.e. you already imported their keys.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;i&gt;    * Can we really guarantee that there are no signed packages available that are exploitable, all the time?&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;That is social-engineering in this case. The policy perfectly worked on rawhide and Fedora 12 Beta because you still need authorization from root to install unsigned packages or when you import keys after you have installed a repository for the first time. It is only with signed packages  that behaviour occurs with &lt;b&gt;PackageKit&lt;/b&gt; on desktop environment. &lt;br /&gt;&lt;br /&gt;The &lt;a href="https://fedoraproject.org/wiki/Features/UserAccountDialog" rel="nofollow"&gt;incoming feature of Fedora 13&lt;/a&gt; only reinforces the original policy from Fedora 12.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/555560888818049373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/555560888818049373'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html?showComment=1258840251385#c555560888818049373' title=''/><author><name>Luya Tshimbalanga</name><uri>http://www.blogger.com/profile/05391142834277609577</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1163343893600586948' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1163343893600586948' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-29404987071597037</id><published>2009-11-21T10:05:42.128-06:00</published><updated>2009-11-21T10:05:42.128-06:00</updated><title type='text'>Very nice.</title><content type='html'>Very nice.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/29404987071597037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/29404987071597037'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html?showComment=1258819542128#c29404987071597037' title=''/><author><name>Steven Pritchard</name><uri>http://www.blogger.com/profile/00716303018104544735</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='11940831743313606259'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1163343893600586948' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1163343893600586948' type='text/html'/></entry><entry><id>tag:blogger.com,1999:blog-8108277809937554792.post-7783471841505491383</id><published>2009-11-20T14:21:33.629-06:00</published><updated>2009-11-20T14:21:33.629-06:00</updated><title type='text'>"This one slipped by us, but I hope the decision w...</title><content type='html'>&amp;quot;This one slipped by us, but I hope the decision will be made to push an update with a more sane default. &amp;quot;&lt;br /&gt;&lt;br /&gt;It already was.&lt;br /&gt;&lt;br /&gt;https://www.redhat.com/archives/fedora-announce-list/2009-November/msg00012.html&lt;br /&gt;&lt;br /&gt;https://www.redhat.com/archives/fedora-devel-list/2009-November/msg01445.html</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/7783471841505491383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8108277809937554792/1163343893600586948/comments/default/7783471841505491383'/><link rel='alternate' type='text/html' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html?showComment=1258748493629#c7783471841505491383' title=''/><author><name>AdamW</name><uri>http://www.blogger.com/profile/01360019761470485694</uri><email>noreply@blogger.com</email></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.stevecoinc.com/2009/11/why-developers-suck-as-admins.html' ref='tag:blogger.com,1999:blog-8108277809937554792.post-1163343893600586948' source='http://www.blogger.com/feeds/8108277809937554792/posts/default/1163343893600586948' type='text/html'/></entry></feed>