On 05/17/2010 03:08 PM, Rahul Sundaram wrote:
On 05/17/2010 06:33 PM, Ralf Corsepius wrote:
>> Did you even try out autodownloader
>> and understand how it works? Doesn't seem like it at all.
>>
> No, I haven't, and I certainly will not try it.
>
.
I don't disagree that RPM packaged data is better but claiming that it
is a attack vector for trojans and viruses without any understanding of
how it works cannot be taken seriously.
Even rpms are an attack vector. They are
not necessarily safer than
packages shipped via other means.
You don't have to try it out
to understand how it works. So that is not a valid reason either.
My point is a bit different: I consider this mechanism to be a way to
*circumvent* rpm as means of packaging and it to be a way of encourage
*sloppyness*, *lazyness* and *carelessness*, which endangers Fedora's users.
If FESCO has a littel understanding, they would have noticed that
"mechanically packaging" game data into rpms and to ship them via repos
is trivial. There is no need to add another mechanism for shipping
packages and to endanger users from the security risks this comes
attached with.
Or differently: One fundamental key of rpm-based distros safety and
consistency has been not to allowing other means of installation.
Ralf