From: Nicholas Van Weerdenburg Date: 2004-08-17T12:21:55+09:00 Subject: Re: RubyForge project and gem distriubtion I can't agree with that. That's exactly how life works. Progress and civilization are based on relying on other people to do most of the work. That lets us focus on more interesting, complex, beneficial and novel problems. Technological advancement is based on automation and simplification. The logistics of programmers having to review all or any significant amount of the code they download is overwhelming. An trust mechanism is an absolute necessity for any non-trivial software, whether distributed as a binary file or source. That trust mechanism can be informal- indeed, the ruby community provides that somewhat. You know who people are after a while, and there are enough eyes looking and information flowing to offer a certain level of security. I already spend too much of my time sleep deprived to have to do security audits of the library code I download (rake, ruby gems itself, DBI, and so on). And, you'd have to do it for each release. Plus, you'd need a PKI identity infrastructure, cerificates, etc. as who's to say you'd find a clever trojan or virus buried in 50 000 lines of ruby code from a non-trivial library. "People who download shouldn't have to be cautious as to look at the code. It should be up to someone else." To me, this is an essential truth, similar to the fact that I shouldn't have to know how an internal combustion engine works to drive a car. Simplication and abstraction- whether in technology or security- is what got us down from the trees, so to speak. Now what is workable is another story. I'm fond of informal implicit security where possible. This list, RubyForge, and the general Ruby Zeitgeist provide a fairly good amount of comfort. I haven't worried about downloading and installing Rake or Iowa because of that. However, having an extra bit of energy in this area does seem to be a good idea. Regards, Nick Francis Hwang wrote: >David Ross wrote in message news:<20040813043743.2642.qmail@web21526.mail.yahoo.com>... > > >>People who download shouldn't have to be cautious as >>to look at the code. It should be up to someone else. >> >> > >A remarkable statement, that. Life would be a lot easier if all sorts >of things were up to somebody else, but that's not how life works. > >Why can't programmers be responsible for the stuff they download? >Nobody's holding a gun to your head forcing you to install a library >as root. > >Francis > > >