ARB security checklist

Shane Fagan shanepatrickfagan at ubuntu.com
Tue Nov 16 22:55:43 UTC 2010


On Tue, 2010-11-16 at 14:50 -0800, Jono Bacon wrote:
> On Tue, 2010-11-16 at 22:47 +0000, Shane Fagan wrote:
> > Oh I do have one question that I think we should talk about. The
> > security team's list of stuff has a $1 charge to do the process to weed
> > out the bad requests and stuff. I dont really agree with it but I see
> > the point in it. I couldnt suggest anything better to work as a filter
> > but id say it would make it a barrier to entry and wouldnt be
> > encouraging for developers to use the process. 
> 
> What is the justification for a dollar charge?
> 
> 	Jono
> 
It would weed out possible spam requests and people using the ARB to get
around the archive with malicious software. It does seem to be a good
idea in theory but id say it would block entry. The entire quote from
the wiki page is 

"developer must sign a developer contract and preferably pay to have an
application considered in PostReleaseApps (eg, $1 USD). Why?

makes sure the developer knows the requirements
discourages anonymity. People are less likely to do intentional harm if
there is a fear of getting caught. Having a signed agreement with credit
card and contact information is a strong social and psychological
deterrent."

--fagan 




More information about the App-review-board mailing list