From: Andreas Krey Date: Fri, 05 Mar 2010 07:36:42 GMT Subject: Re: Question about scm security holes Message-ID: <20100305073642.GA16131@inner.home.ulmdo.de> In-Reply-To: <32541b131003041803q9abf6baq4cf9ffcca990b51c@mail.gmail.com> On Thu, 04 Mar 2010 21:03:08 +0000, Avery Pennarun wrote: ... > where every single developer workstation has a complete copy of the > entire project history anyway. It's the point of a dev workstation to have access to the code, so McAfees whining about SCMs letting that happen is moot. What would be helping here is a separation between internet-facing and local work into separate machines. > least. Traceable, not so much, because you can create a commit with > whatever committer/author names you want and then push them in. You can still log who pushed what into your blessed repo, and hold that person accountable. Andreas