summaryrefslogtreecommitdiffstats
path: root/zarb-ml/mageia-discuss/20110704/004900.html
diff options
context:
space:
mode:
Diffstat (limited to 'zarb-ml/mageia-discuss/20110704/004900.html')
-rw-r--r--zarb-ml/mageia-discuss/20110704/004900.html101
1 files changed, 101 insertions, 0 deletions
diff --git a/zarb-ml/mageia-discuss/20110704/004900.html b/zarb-ml/mageia-discuss/20110704/004900.html
new file mode 100644
index 000000000..a464279ba
--- /dev/null
+++ b/zarb-ml/mageia-discuss/20110704/004900.html
@@ -0,0 +1,101 @@
+<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
+<HTML>
+ <HEAD>
+ <TITLE> [Mageia-discuss] mageiaupdate and the list of updates
+ </TITLE>
+ <LINK REL="Index" HREF="index.html" >
+ <LINK REL="made" HREF="mailto:mageia-discuss%40mageia.org?Subject=Re%3A%20%5BMageia-discuss%5D%20mageiaupdate%20and%20the%20list%20of%20updates&In-Reply-To=%3C1309736820.10671.18.camel%40akroma.ephaone.org%3E">
+ <META NAME="robots" CONTENT="index,nofollow">
+ <META http-equiv="Content-Type" content="text/html; charset=us-ascii">
+
+ <LINK REL="Next" HREF="004905.html">
+ </HEAD>
+ <BODY BGCOLOR="#ffffff">
+ <H1>[Mageia-discuss] mageiaupdate and the list of updates</H1>
+ <B>Michael Scherer</B>
+ <A HREF="mailto:mageia-discuss%40mageia.org?Subject=Re%3A%20%5BMageia-discuss%5D%20mageiaupdate%20and%20the%20list%20of%20updates&In-Reply-To=%3C1309736820.10671.18.camel%40akroma.ephaone.org%3E"
+ TITLE="[Mageia-discuss] mageiaupdate and the list of updates">misc at zarb.org
+ </A><BR>
+ <I>Mon Jul 4 01:46:59 CEST 2011</I>
+ <P><UL>
+
+ <LI>Next message: <A HREF="004905.html">[Mageia-discuss] mageiaupdate and the list of updates
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#4900">[ date ]</a>
+ <a href="thread.html#4900">[ thread ]</a>
+ <a href="subject.html#4900">[ subject ]</a>
+ <a href="author.html#4900">[ author ]</a>
+ </LI>
+ </UL>
+ <HR>
+<!--beginarticle-->
+<PRE>Le samedi 02 juillet 2011 &#224; 19:40 -0400, andre999 a &#233;crit :
+&gt;<i> Anne nicolas a &#233;crit :
+</I>&gt;<i> &gt; 2011/7/2 Romain d'Alverny&lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">rdalverny at gmail.com</A>&gt;:
+</I>&gt;<i> &gt;&gt; Le 2 juil. 2011 &#224; 17:14, andre999&lt;<A HREF="https://www.mageia.org/mailman/listinfo/mageia-discuss">andr55 at laposte.net</A>&gt; a &#233;crit :
+</I>&gt;<i> &gt;&gt;&gt; Suppose during the update process you have a check box to put a particular update on
+</I>&gt;<i> &gt;&gt;&gt; the skip list, or another to uninstall the corresponding package.
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt; That would be an interesting option to investigate.
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt;&gt; Note that if you can't uninstall a package because it is required, it is usually
+</I>&gt;<i> &gt;&gt;&gt; inadvisable skip updates, unless you really understand the issues.
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt; So the user is stuck: unadvisable to skip the updates, unless she understands the issues
+</I>&gt;<i> &gt;&gt; =&gt; just make the update automatic in a background task by default then; one doesn't care
+</I>&gt;<i> &gt;&gt; about the issues - or won't have a single clue about it either, unless being a specific
+</I>&gt;<i> &gt;&gt; type of user that would know how to disable this auto update setting anyway).
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt;&gt; Changing when the password is requested would reduce the security for the system, as
+</I>&gt;<i> &gt;&gt;&gt; unauthorised users could see what is installed.
+</I>&gt;<i> &gt;&gt;
+</I>&gt;<i> &gt;&gt; Unauthorised users using an authorised session, to be more specific.
+</I>&gt;<i>
+</I>&gt;<i> Such a situation is far from rare in multi-user environments.
+</I>&gt;<i> But also if someone doesn't know the root password, currently they can't see
+</I>&gt;<i> what is installed. By delaying it until something is actually updated, they can
+</I>&gt;<i> see everything. So a remote user with limited privileges could more easily
+</I>&gt;<i> compromise the system.
+</I>
+They can use rpm -qa on the terminal to know what is installed.
+
+And they can use urpmq --auto-select to see the current update.
+
+In fact, one reason to not ask password before updating would simply be
+to decide if we update now, or later, due to various network related
+reason ( like using 3g, or slow wifi ). If I see a update of
+libreoffice, I would prefer do it at home.
+
+And there is no technical reasons to ask for password before displaying
+so I think we should ask it only for important reason ( ie, really
+update ).
+This would be consistent with others os ( os x ask the password only we
+choose to update, so does Fedora/packagekit and Ubuntu/apt-daemon ).
+
+--
+Michael Scherer
+
+</PRE>
+
+
+
+<!--endarticle-->
+ <HR>
+ <P><UL>
+ <!--threads-->
+
+ <LI>Next message: <A HREF="004905.html">[Mageia-discuss] mageiaupdate and the list of updates
+</A></li>
+ <LI> <B>Messages sorted by:</B>
+ <a href="date.html#4900">[ date ]</a>
+ <a href="thread.html#4900">[ thread ]</a>
+ <a href="subject.html#4900">[ subject ]</a>
+ <a href="author.html#4900">[ author ]</a>
+ </LI>
+ </UL>
+
+<hr>
+<a href="https://www.mageia.org/mailman/listinfo/mageia-discuss">More information about the Mageia-discuss
+mailing list</a><br>
+</body></html>