Usage of apturl in the documentation

Dougie Richardson ddrichardson at btinternet.com
Fri Sep 26 16:59:37 UTC 2008


> I chatted to Michael about this today on irc, and he confirmed that
> apturl is safe to use on the help wiki and system documentation, as it
> only installs packages from the user's repositories.

What if the guide they are reading directs them to add another, malicious
repository?

I understand the benefits but really wouldn't want to see this is the
community documentation. As was displayed by the (still open) Google 402
exploit bug, it is frustratingly slow to have an exploit fixed. Most of that
was spent arguing.

I'm sure everyone knows what they are talking about but is it really a good
idea to introduce a possible vulnerability?

Cheers,

Dougie






More information about the ubuntu-doc mailing list