[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Integrating package.el

From: Ted Zlatanov
Subject: Re: Integrating package.el
Date: Wed, 06 Jan 2010 15:49:05 -0600
User-agent: Gnus/5.110011 (No Gnus v0.11) Emacs/23.1.90 (gnu/linux)

On Wed, 06 Jan 2010 15:45:37 -0500 Richard Stallman <address@hidden> wrote: 

>> The package repositories should be identified by a single URL; the ones
>> that come with Emacs should point to a secure Savannah URL.  That may
>> address RMS' concerns about loading software over the network.  

RS> Alas that doesn't affect the issue.  Running software directly from
RS> the network is bad because it is a process that invites users to give
RS> up control.

RS> Who wrote the program makes no difference, not for this.
RS> Where the program comes from makes no difference.
RS> Suppose I wrote the program and people fetch it from gnu.org:
RS> that makes no difference.  It is still bad for people to
RS> adopt a practice that gives them less control.

RS> So we won't lead people in that direction.

Sorry for confusing the issue between the package.el discussion and
Lennart's discussion.  I was talking about installing software, not
running it directly from the repository.  I would expect packages to be
signed by the package repository maintainer as well, ensuring integrity.


reply via email to

[Prev in Thread] Current Thread [Next in Thread]