maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Community (https://talk.maemo.org/forumdisplay.php?f=16)
-   -   [Testing Squad] - April 2010 (https://talk.maemo.org/showthread.php?t=49230)

thp 2010-04-11 19:15

Re: [Testing Squad] - April 2010
 
Quote:

Originally Posted by Jaffa (Post 605686)
Any daemon which auto-starts MUST NOT provide a trivial attack vector, and so SHOULD (for example) prompt for a password during installation.

What's defined as "trivial attack vector", and which kind of password is to be prompted during installation? Isn't that a hassle for the user to always enter a password during installation (and maybe upgrade) of a daemon? (I'm specifically thinking of headphoned here, because this change would probably affect my package and cause more work with no real benefit for me or the user in the case of headphoned)

Jaffa 2010-04-11 19:22

Re: [Testing Squad] - April 2010
 
Quote:

Originally Posted by thp (Post 605799)
What's defined as "trivial attack vector", and which kind of password is to be prompted during installation? Isn't that a hassle for the user to always enter a password during installation (and maybe upgrade) of a daemon? (I'm specifically thinking of headphoned here, because this change would probably affect my package and cause more work with no real benefit for me or the user in the case of headphoned)

The most obvious example of a "trivial attack vector" being if OpenSSH server didn't prompt for a new root password. The factory root password of Maemo is well known, and the daemon is started at runtime.

headphoned doesn't listen on any remote port and only communicates with Bluetooth (AIUI, although it doesn't pause when my BT headphones disconnect, so maybe I misread that).

Perhaps it'd be better defined as "trivial remote attack vector"?

Texrat 2010-04-11 19:43

Re: [Testing Squad] - April 2010
 
Sounds like a plan.

lma 2010-04-11 22:59

Re: [Testing Squad] - April 2010
 
Quote:

Originally Posted by Jaffa (Post 605686)
  • An application MUST use the standard CLI icon, or the standard CLI badge over an alternative icon, if the user must use X Terminal to start the main purpose of the application.

Well put, though "main purpose" may leave some gray areas.

Quote:

  • Packages which auto-start in a secure manner, or enable alternative functionality in other applications, SHOULD NOT use the CLI icon, as interaction with them through the CLI is not required.

I would s/in a secure manner// (not relevant to the icon rules, and having it there may give the impression that auto-starting insecurely is ok if there's a CLI icon).

Quote:

  • Any daemon which auto-starts MUST NOT provide a trivial attack vector, and so SHOULD (for example) prompt for a password during installation.

Let's leave this out (or add it explicitly to the security part of the QA checklist), it has no relevance to the icon / description rules either.

slender 2010-05-31 12:50

Re: [Testing Squad] - April 2010
 
Do we have May list? Probably itīs "bit" late but then June list maybe?

torpedo48 2010-05-31 13:07

Re: [Testing Squad] - April 2010
 
Quote:

Originally Posted by slender (Post 691655)
Do we have May list? Probably itīs "bit" late but then June list maybe?

It's been a very long time since the last list: I can write them, but I don't think there are enough testers for making them useful. Personally I've continued the testing and voted as many apps as I can, but the queue is getting longer every day (this is the first time I see page 5).

However, if you say there are testers, I'll create a list.

slender 2010-05-31 13:16

Re: [Testing Squad] - April 2010
 
I do not know if there is more testers, but monthly "advertisement" about this is not bad IMHO :) There is more and more users but in this jungle of information here nobody knows where to begin or what is happening here and some direction sign are always useful ;)

mikkov 2010-05-31 13:23

Re: [Testing Squad] - April 2010
 
Here's a list of packages in testing queue http://maemo.org/packages/repository...in_repo_page=5 . What more lists are really needed?

You can start from any part of the list and test as many applications as you wish. If application has already 10 votes or more, more testing is not necessarily needed.

torpedo48 2010-05-31 13:27

Re: [Testing Squad] - April 2010
 
Quote:

Originally Posted by slender (Post 691711)
I do not know if there is more testers, but monthly "advertisement" about this is not bad IMHO :) There is more and more users but in this jungle of information here nobody knows where to begin or what is happening here and some direction sign are always useful ;)

You know what? You are definitively right. Tomorrow i'll create a new list, and I'll try to "hire" as many new testers as I can. Something like "Maemo.org Testing Squad WANTS YOU" or similar.

The new list will focus on apps that needs just a few votes in order to reach Extras, hope that will clean the queue a bit. I'll also insert a Vote Down section for removing not-ready apps.

slender 2010-05-31 13:27

Re: [Testing Squad] - April 2010
 
@mikkov
IMHO all talking (Just guess that not many users follow other areas of maemo.org) here evoke people to do testing and experiment their N900.

Now everything is probably crystal clear for people who have been here for ~4 months, but new potential users and users who have forgot this can get idea.

All in all I think that all the little projects what you have going on here need little advertisement once in awhile. Itīs not always bad.

.edit
It doesnīt always get people going (looks/feels like waste of time) but you can be sure that if you are not on view at all then itīs quite probable that no-one knows or will know about you.


All times are GMT. The time now is 23:13.

vBulletin® Version 3.8.8