IRC log for #gllug on 20120814

06:51.17*** join/#gllug ess_tee_u (~NULL@94-30-86-45.xdsl.murphx.net)
11:13.06*** join/#gllug AndyMill1r (~andy-free@andymillar.co.uk)
12:33.35*** join/#gllug dick_turpin (~peter@host217-34-163-30.in-addr.btopenworld.com)
12:36.08dick_turpinOggCamp
14:06.22LeedsWMVConf
14:33.45ChoHagMercurial.
14:33.47ChoHagIt is shit.
14:34.26yaMattI kind of like it
14:34.34yaMattit's like someone tried to make svn work like git
14:34.39ChoHagSomebody always does.
14:50.42ChoHagImagine the following scenario:
14:50.42ChoHagAlice has a repository in /repos/alice/project
14:50.42ChoHagIt contains a .hg/hgrc owned by Alice
14:50.43ChoHagBob looks at the repository with hg log
14:50.58ChoHagIf Bob's hg command trusted Alice's .hg/hgrc, then it could be tricked into loading and running whatever hooks, extensions, and so forth that Alice had configured. If Alice was malicious, she could set up a hook to give her access to Bob's account, read his mail, personal files, etc.
14:51.10ChoHagOr Bob could, you know, not run shit from somebody else?
14:54.00ChoHagMaking me switch to root just to read a publicly-owned set of files is slightly ridiculous.
14:54.14ChoHagAlso I think root probably isn't malicious.
14:55.19yaMattcouldn't you do that with git though? It has hooks too
14:55.33ChoHagBut probably the good sense not to run them when it doesn't need to.
18:22.08*** join/#gllug Armand (~androirc@cpc17-haye16-2-0-cust427.haye.cable.virginmedia.com)
23:35.26*** join/#gllug Leeds (~richardc@168.70.79.81)

Generated by irclog2html.pl Modified by Tim Riker to work with infobot.