[Pkg-utopia-maintainers] Bug#526854: hal: HAL should not require PolicyKit

Michael Biebl biebl at debian.org
Mon May 4 07:52:20 UTC 2009


severity 526854 wishlist
tags 526854 wontfix
thanks

Fredrik Tolf wrote:
> Package: hal
> Version: 0.5.12~git20090406.46dc48-2
> Severity: important
> 
> 
> I think that it is a bad thing that HAL started depending on PolicyKit in the
> latest versions. PolicyKit introduces a whole new, parallel security system,
> and it does not seem to be well-known how it works or how to properly
> administer it (I, for one, certainly don't know how it works, at least).
> 
> Therefore, it may introduce security holes unknown to the maintainer of some
> systems. In particular seeing how HAL is required by so many things (GNOME and
> KDE, for example), it may even install PolicyKit without the administrator
> knowing about it (installing GNOME or KDE pulls in so many other packages
> anyway that it might be hard to spot PolicyKit among them; I almost missed it
> in the latest dist-upgrade).
> 
> I have not researched it in detail yet, so I don't really know if it's a good

So you are basing your request on FUD?

Michael
-- 
Why is it that all of the instruments seeking intelligent life in the
universe are pointed away from Earth?

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 260 bytes
Desc: OpenPGP digital signature
URL: <http://lists.alioth.debian.org/pipermail/pkg-utopia-maintainers/attachments/20090504/e40606f2/attachment.pgp>


More information about the Pkg-utopia-maintainers mailing list