Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Don Armstrong
On Thu, 11 Apr 2013, Russ Allbery wrote: > Sandboxing programming languages is very difficult; most languages > don't even attempt it. Perl used to have a sandboxing module and > gave up on it because it was too hard, thus making it even less > secure than Java in that specific respect, but no one

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Russ Allbery
Thomas Goirand writes: > On 04/12/2013 03:25 AM, Tollef Fog Heen wrote: >> The Yubikey neo can run the java applet thingies, it seems, so it can >> act as a GPG token too. > Please, please, please ... no java!!! That's a security nightmare. I > think we'd be less safe with than without it. You

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Tollef Fog Heen
]] Thomas Goirand > On 04/12/2013 03:25 AM, Tollef Fog Heen wrote: > > The Yubikey neo can run the java applet thingies, it seems, so it can > > act as a GPG token too. > Please, please, please ... no java!!! > That's a security nightmare. I think we'd be less safe with > than without it. Pleas

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Daniel Pocock
On 12/04/13 07:56, Thomas Goirand wrote: > On 04/12/2013 03:25 AM, Tollef Fog Heen wrote: >> The Yubikey neo can run the java applet thingies, it seems, so it can >> act as a GPG token too. > Please, please, please ... no java!!! > That's a security nightmare. I think we'd be less safe with > th

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Thomas Goirand
On 04/12/2013 03:25 AM, Tollef Fog Heen wrote: > The Yubikey neo can run the java applet thingies, it seems, so it can > act as a GPG token too. Please, please, please ... no java!!! That's a security nightmare. I think we'd be less safe with than without it. Also, while I think the idea is nice,

Bug#705256: ITP: libparallel-runner-perl -- Perl module to manage running things in parallel processes

2013-04-11 Thread Xavier Guimard
Package: wnpp Severity: wishlist Owner: Xavier Guimard * Package name: libparallel-runner-perl Version : 0.012 Upstream Author : Chad Granum * URL : https://metacpan.org/release/Fennec * License : Artistic or GPL-1+ Programming Lang: Perl Description :

Work-needing packages report for Apr 12, 2013

2013-04-11 Thread wnpp
The following is a listing of packages for which help has been requested through the WNPP (Work-Needing and Prospective Packages) system in the last week. Total number of orphaned packages: 513 (new: 10) Total number of packages offered up for adoption: 147 (new: 2) Total number of packages reques

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Martin Zobel-Helas
Hi, On Thu Apr 11, 2013 at 19:04:24 -0300, Lisandro Damián Nicanor Pérez Meyer wrote: > On Thu 11 Apr 2013 16:04:40 Luca Filipozzi escribió: > [snip] > > Finally, if we are going to require DDs to have a physical object ^^ || > In other words: -1 from me. I read Luca

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Lisandro Damián Nicanor Pérez Meyer
On Thu 11 Apr 2013 16:04:40 Luca Filipozzi escribió: [snip] > Finally, if we are going to require DDs to have a physical object Then the project would possibly start loosing contributors like me, who have lots of problems with customs and getting dollars, specially if it's about technological st

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Luca Filipozzi
On Thu, Apr 11, 2013 at 03:35:35PM -0400, Paul Tagliamonte wrote: > I really hate the idea of "loosing" an unencrypted copy of my GPG > private half. I misplace everything, I don't need someone finding a copy > of my GPG key and abusing it :) You write the private key to the token. You can't read

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Martin Zobel-Helas
Hi, > Aslo, we have sso.debian.org, whose use we should expand. DACS (http://dacs.dss.ca) the software behind sso.debian.org also support one-time passwords [1]. I had no time yet to setup anything regarding this, but I welcome help. Cheers, Martin [1] http://dacs.dss.ca/man/dacstoken.1.html

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Jonathan Dowland
On Thu, Apr 11, 2013 at 07:04:40PM +, Luca Filipozzi wrote: > Aslo, we have sso.debian.org, whose use we should expand. I'd love to see that. -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archi

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Daniel Pocock
On 11/04/13 21:25, Tollef Fog Heen wrote: > ]] Luca Filipozzi > >> I can help with a GSoC but I think DSA would prefer to lean in the direction >> of >> the above. > > I'm also happy to help with it. I have a bit of experience with the > yubikey tokens, and at least one of the upstreams is on

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Paul Tagliamonte
On Thu, Apr 11, 2013 at 09:25:02PM +0200, Tollef Fog Heen wrote: > ]] Luca Filipozzi > > > I can help with a GSoC but I think DSA would prefer to lean in the > > direction of > > the above. > > I'm also happy to help with it. I have a bit of experience with the > yubikey tokens, and at least o

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Tollef Fog Heen
]] Luca Filipozzi > I can help with a GSoC but I think DSA would prefer to lean in the direction > of > the above. I'm also happy to help with it. I have a bit of experience with the yubikey tokens, and at least one of the upstreams is on the path to DDship, so I think we're reasonably well co

Re: Debian two-factor auth, GSoC?

2013-04-11 Thread Luca Filipozzi
Hi, DSA are already looking at two factor authentication, but TOTP based rather than HOTP. There are plenty of TOTP calculators that could be deployed on smart phones, etc. rather than requiring DDs to own a YubiKey (and have USB port available... i wonder if my iPad has a USB port...). Interest

Debian two-factor auth, GSoC?

2013-04-11 Thread Daniel Pocock
Fedora recently put in Yubikey for their packagers[1], although they are only half way there, supporting sudo but not web auth so far. Similar things could probably happen in Debian. I've proposed two-factor authentication as a potential area for a GSoC project[2], two things come up: a) would

Re: FPM in Debian archive [Was: Re: Bug#704686: ITP: ruby-arr-pm -- RPM reader and writer Ruby library]

2013-04-11 Thread Guillem Jover
On Thu, 2013-04-11 at 11:50:35 +0200, Laurent Bigonville wrote: > > Jon Dowland wrote: > > >Hi Laurent, thanks for the clarification â?? to ask a related > > >question. What's the worth of FPM on Debian? Especially given the > > >issues that Wouter has raised in the bug¹ > > > > > >¹ http://bugs.

Bug#705221: ITP: pcapfix -- repair broken pcap files

2013-04-11 Thread Joao Eriberto Mota Filho
Package: wnpp Severity: wishlist Owner: Joao Eriberto Mota Filho * Package name: pcapfix Version : 0.7.2 Upstream Author : Robert Krause * URL : http://f00l.de/pcapfix * License : GPL3 Programming Lang: C Description : repair broken pcap files pcapfi

Bug#705212: ITP: chinese-checkers -- Multiplayer implementation of the chinese checkers game.

2013-04-11 Thread Salvo Tomaselli
Package: wnpp Severity: wishlist Owner: Salvo Tomaselli * Package name: chinese-checkers Version : 0.1 Upstream Author : Many authors * URL : https://github.com/ltworf/tin171 * License : GPL Programming Lang: Python, Erlang Description : Multiplayer imp

Re: Crypto export

2013-04-11 Thread Charles Plessy
Le Thu, Apr 11, 2013 at 08:27:16AM +0200, Joerg Jaspert a écrit : > > https://ftp-master.debian.org/crypto-in-main/ > > Plus one mail for *every* NEW accepted package. Each and every time. > Send to them.[1] See the dak git repo for the bxa stuff. > > > [1] Nowadays only stored in a mailbox fro

Re: Crypto export

2013-04-11 Thread Alberto Fuentes
On 04/11/2013 08:27 AM, Joerg Jaspert wrote: > > https://ftp-master.debian.org/crypto-in-main/ > > Plus one mail for *every* NEW accepted package. Each and every time. > Send to them.[1] See the dak git repo for the bxa stuff. > > > [1] Nowadays only stored in a mailbox from us, at request from

Bug#705206: ITP: compass-breakpoint-plugin -- really simple media queries with Sass

2013-04-11 Thread Jonas Smedegaard
Package: wnpp Severity: wishlist Owner: Jonas Smedegaard * Package name: compass-breakpoint-plugin Version : 2.0.2 Upstream Author : Mason Wendell , Sam Richard * URL : https://github.com/Team-Sass/breakpoint * License : Expat or GPL-2 Programming Lang: Sas

FPM in Debian archive [Was: Re: Bug#704686: ITP: ruby-arr-pm -- RPM reader and writer Ruby library]

2013-04-11 Thread Laurent Bigonville
> Jon Dowland wrote: > >On Tue, Apr 09, 2013 at 05:33:20PM +0200, Laurent Bigonville wrote: > >> This ruby gem is needed by FPM (see my ITP[0]). > > > >Hi Laurent, thanks for the clarification â?? to ask a related > >question. What's the worth of FPM on Debian? Especially given the > >issues that W

Re: Bug#705169: RFH: iproute2 -- networking and traffic control tools

2013-04-11 Thread Andreas Henriksson
Hello again! Given the very positive response on my RFH I'm following up with one more wish I forgot to mention. If you are interested in learning more about the advanced networking features provided by the linux kernel. Want to get into the gory details and learn stuff that not many other pe

Re: Bug#705169: RFH: iproute2 -- networking and traffic control tools

2013-04-11 Thread Andreas Henriksson
Hello Thomas! On Wed, Apr 10, 2013 at 10:32:48PM +0200, Thomas Preud'homme wrote: > Le mercredi 10 avril 2013 21:33:32, Andreas Henriksson a écrit : [...] > > "Please perform a full source scan and document all licensing information." > > As requested by ftp-masters. > > I didn't find a bug repor