On Mon, Aug 6, 2012 at 10:46 AM, Micah Gersten
<email address hidden> wrote:
> I would think a configurable option per team would be much better for
> this defaulting to off. I don't think teams like bugcontrol would be
> appropriate to have any member be able to create PPAs. While we trust
> various members with private bug information, packaging is a whole
> different story.
And some teams will trust some folk more than others. Thats fine, I
don't think LP has to model this exactly. The key things are that
anyone creating a PPA in a socially privileged context be accountable
for it, and that it be deletable if its inappropriate.
Both of those things are satisfied with what I propose.
Why do I suggest that those things are the key? Because they allow any
abuse to be corrected, in a reasonable timeframe.
If you're worried about social engineering attacks, consider that
anyone can create a plausible looking team name anyway...
On Mon, Aug 6, 2012 at 10:46 AM, Micah Gersten
<email address hidden> wrote:
> I would think a configurable option per team would be much better for
> this defaulting to off. I don't think teams like bugcontrol would be
> appropriate to have any member be able to create PPAs. While we trust
> various members with private bug information, packaging is a whole
> different story.
And some teams will trust some folk more than others. Thats fine, I
don't think LP has to model this exactly. The key things are that
anyone creating a PPA in a socially privileged context be accountable
for it, and that it be deletable if its inappropriate.
Both of those things are satisfied with what I propose.
Why do I suggest that those things are the key? Because they allow any
abuse to be corrected, in a reasonable timeframe.
If you're worried about social engineering attacks, consider that
anyone can create a plausible looking team name anyway...