Re: Question about scm security holes
- From
Andreas Krey <a.krey@gmx.de>
- Date
- Mar 5, 2010, 07:36 UTC
- Message-ID
- <20100305073642.GA16131@inner.home.ulmdo.de>
- In-Reply-To
- <32541b131003041803q9abf6baq4cf9ffcca990b51c@mail.gmail.com>
On Thu, 04 Mar 2010 21:03:08 +0000, Avery Pennarun wrote: ...
> where every single developer workstation has a complete copy of the > entire project history anyway.
It's the point of a dev workstation to have access to the code, so McAfees whining about SCMs letting that happen is moot.
What would be helping here is a separation between internet-facing and local work into separate machines.
> least. Traceable, not so much, because you can create a commit with > whatever committer/author names you want and then push them in.
You can still log who pushed what into your blessed repo, and hold that person accountable.
Andreas