<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title><![CDATA[Please reconsider: Ability to add repositories via URL (apturl, gdebi)]]></title>
    <link>http://brainstorm.ubuntu.com/item/12753/</link>
    <description><![CDATA[While it is true that third party repositories AND third party packages mean a potential harm to the users system, the current handling of third-party software is not consistent. <br /><br />The success of getdeb.net and the launchpad PPA's show a demand for third party software. Installing a Ubuntu package via gdebi is easy and used frequently.<br /><br />Even when installed from a trustworthy source, installation of single DEB-packages cause a security risk due to a lack of updates. IF the user decides to install third-party software, it seems just consistent to offer him a comparable easy way of adding a repository. This way, his software will get updated and he will decrease the risk of possible security holes due to outdated software.<br /><br />
<br />


]]></description>

    <language>en-us</language>
    <pubDate>Tue, 02 Sep 2008 23:07:14 +0000</pubDate>
    <lastBuildDate>Wed, 22 Oct 2008 17:41:42 +0000</lastBuildDate>
    <generator>QAPoll module</generator>
    <guid isPermaLink="true">http://brainstorm.ubuntu.com/idea/12753/</guid>
        <item>
  <title>Comment from retj</title>
  <description><![CDATA[One click install then?]]></description>
  <pubDate>Wed, 03 Sep 2008 07:00:28 +0000</pubDate>
</item>
        <item>
  <title>Comment from thielmann</title>
  <description><![CDATA[Not necessarily one click, but no click-click-click-click-click-copy-paste-click-click-click-wait-click. :-) ]]></description>
  <pubDate>Wed, 03 Sep 2008 10:15:37 +0000</pubDate>
</item>
        <item>
  <title>Comment from lutfiarab</title>
  <description><![CDATA[Yes. U right<br />Adding repository suck for ordinary user<br />better open again]]></description>
  <pubDate>Wed, 03 Sep 2008 12:44:27 +0000</pubDate>
</item>
        <item>
  <title>Comment from retj</title>
  <description><![CDATA[I meant using Opensuse' feature: One Click install, its basically what you say, i've posted it many times, but people hated the idea becouse of ''security issues, which i find kind of stupid becouse it has the same risks as .deb installation.]]></description>
  <pubDate>Wed, 03 Sep 2008 13:14:04 +0000</pubDate>
</item>
        <item>
  <title>Comment from Vadim P.</title>
  <description><![CDATA[Well, it sort of is possible, see how playdeb did it: http://www.playdeb.net/]]></description>
  <pubDate>Wed, 03 Sep 2008 17:31:51 +0000</pubDate>
</item>
        <item>
  <title>Comment from Ubun2ideas</title>
  <description><![CDATA[Adding a repository is not an action that should be taken lightly.  Bear in mind, when you get a notification for updates, it doesn't spell out for you which repositories are pushing which updated packages.  How difficult would it be to abuse this system? - not very.  You're basically extending a great deal of trust to the maintainer of the repos you add.  <br /><br />]]></description>
  <pubDate>Thu, 04 Sep 2008 03:33:51 +0000</pubDate>
</item>
        <item>
  <title>Comment from Warbo</title>
  <description><![CDATA[Repositories can be added as easily as packages, since repositories are text files in /etc/apt/sources.list.d. If something more complicated than a static file is needed (eg. making a cross-release package which auto-detects the release it's being installed on) then pre-install, post-install, pre-remove and post-remove scripts can be used (just like every package). If the user should be asked whether the repository is added or not then use debconf.<br /><br />There is NOTHING new to be done, as far as I see it. It's all possible right now just by making a package (we have GDebi to make package installation painless, although I don't know if it's assigned to downloaded Debian packages by default since I don't use Firefox)]]></description>
  <pubDate>Thu, 04 Sep 2008 04:55:56 +0000</pubDate>
</item>
        <item>
  <title>Comment from Moredhas</title>
  <description><![CDATA[It's a bit of a security risk, IMO, and a blunder that could be remembered as on a par with ActiveX controls in IE6.  All that would be required to compromise the system is for a malicious page to slip Firefox an apt:// URL while you happen to have Synaptic open as root.  I don't know how most do it, but if I search Synaptic and find that something's not in the repositories, I go looking for a repository to add and leave Synaptic open in the background.  If what I do is anything even vaguely resembling normal, that's a lot of Ubuntu installs that could be attacked by a malware-laced repository.]]></description>
  <pubDate>Fri, 05 Sep 2008 08:58:02 +0000</pubDate>
</item>
        <item>
  <title>Comment from Endolith</title>
  <description><![CDATA[Please make this easier to do.  Put up a big fat warning, but make it easy to do.]]></description>
  <pubDate>Fri, 05 Sep 2008 14:36:25 +0000</pubDate>
</item>
        <item>
  <title>Comment from Ubun2ideas</title>
  <description><![CDATA[@Endolith: I guess I'm inclined to agree, *provided* the warning cannot be easily disabled, and only sudoers can add repos.]]></description>
  <pubDate>Fri, 05 Sep 2008 19:30:02 +0000</pubDate>
</item>
        <item>
  <title>Comment from Warbo</title>
  <description><![CDATA[debconf can already be used for warnings....]]></description>
  <pubDate>Sat, 06 Sep 2008 00:45:55 +0000</pubDate>
</item>
        <item>
  <title>Comment from adelie</title>
  <description><![CDATA[average users should not be adding repos. Just check the news for XSS / XSRF vulnerabilities, and just imagine the possibilities of handing over root to your 'friends' on myspace.<br /><br />The idea of a few clicks between anywhere on the internet to root should have some serious boundaries. system -> administration -> Software sources -> Third party, copy paste, reload. VERY easy, and not scriptable. Requires easy, but DELIBERATE on part of an administrator.<br /><br />Haven't we learned our lesson with dangerous one click actions with warning dialogs?? Or are we just going to add CAPTCHAS on all the warning dialogs to make people read them. Uggh! ]]></description>
  <pubDate>Thu, 16 Oct 2008 18:02:07 +0000</pubDate>
</item>
        <item>
  <title>Comment from Warbo</title>
  <description><![CDATA[There's a delicate balance between controlling one's machine, and messing it up easily. There is no such thing as an "average users should not be XYZ", in the same way that we're not all using 640K of RAM.<br /><br />Placing arbitrary limits on what "should" or "should not" be the case is a broken way of thinking. The fact is that everything proposed in this idea is completely do-able right now, on every Ubuntu, Debian and Debian-derived system in the world. It probably applies to every RPM system too, but I only ever used RPM through Apt4RPM. Saying it 'should not' be do-able because nefarious people could cause harm is wrong, since those wishing to do harm are clued-up enough to do it already. Those who don't already know how to do it are the "average users" who would benefit from this stuff.<br /><br />However, that's a generic argument. As for this idea, it is completely redundant as I've already stated that it's all possible already.]]></description>
  <pubDate>Thu, 16 Oct 2008 20:56:24 +0000</pubDate>
</item>
        <item>
  <title>Comment from chipbennett</title>
  <description><![CDATA[@Moredhas:<br /><br />Should apturl be able to modify sources.list if Synaptic is already open?<br /><br />Wouldn't the most logical functionality be that Synaptic would have to be closed before apturl could do anything? (I'm envisioning what would happen if, say, Synaptic is open, and the user tries to open Add/Remove. Synaptic already has "control" of APT, and has to be closed before Add/Remove can have it.<br /><br />That way, apturl would require explicit entry of SUDO password - preventing a malicious web site from adding a malicious repo.]]></description>
  <pubDate>Wed, 22 Oct 2008 17:41:42 +0000</pubDate>
</item>
      </channel>
</rss>
