Bug#752201: ITP: yowsup -- library to implement a Whatsapp client

2014-06-20 Thread Joao Eriberto Mota Filho
Package: wnpp Severity: wishlist Owner: Joao Eriberto Mota Filho * Package name: yowsup Version : 0.0~git20140314.938cf1 Upstream Author : Tarek Galal * URL : https://github.com/tgalal/yowsup * License : MIT Programming Lang: Python Description : libra

Re: HTTPS everywhere!

2014-06-20 Thread Christoph Anton Mitterer
On Sat, 2014-06-21 at 03:41 +0200, Matthias Urlichs wrote: > Christoph Anton Mitterer: > > In OpenPGP you have the additional problems that: > > - at least until know communication with the keyservers is usually > > unsecured: so not only the keyserver operator can attack you, but anyone > > else

Re: HTTPS everywhere!

2014-06-20 Thread Matthias Urlichs
Hi, Christoph Anton Mitterer: > In OpenPGP you have the additional problems that: > - at least until know communication with the keyservers is usually > unsecured: so not only the keyserver operator can attack you, but anyone > else that can MitM. Fortunately, that only matters when checking for

Re: HTTPS everywhere!

2014-06-20 Thread Christoph Anton Mitterer
On Wed, 2014-06-18 at 10:05 -0700, Russ Allbery wrote: > This is only true if the root CA is maintained with the same level of > security as the PGP signing key for the archive. Well and currently, people trust GANDI when they download (then possibly forged) Debian images? Actually even less, sinc

Bug#752193: Severity of bug from Submitter's PoV in BTS

2014-06-20 Thread Don Armstrong
Package: debbugs Severity: wishlist On Fri, 20 Jun 2014, Paul Tagliamonte wrote: > Say what you want about launchpad.net's bugtracker (I, for one, like > it), it at least has the status 'opinion'. I miss that, and sometimes, I > wish I could set it in the BTS. Whos' in the patching mood? On some

Re: HTTPS everywhere!

2014-06-20 Thread Christoph Anton Mitterer
On Wed, 2014-06-18 at 15:29 +0200, Vincent Lefevre wrote: > At least you > need some 3rd party to check certificate revocation. But if it is > malicious, it could tell you that the certificate has been revoked > (even if it isn't), and you have the same problem as now... well, > almost. It's actu

Re: HTTPS everywhere!

2014-06-20 Thread Christoph Anton Mitterer
On Wed, 2014-06-18 at 14:20 +1000, Russell Stuart wrote: > Precisely. It has a horrible design bug. > > Given the nature of the net, where we want to deal securely with some > entity never dealt with or of heard of before like, www.shop.com, we > are forced to rely on a third party to assure us

Re: improving downloader packages (was: Re: holes in secure apt)

2014-06-20 Thread Christoph Anton Mitterer
On Fri, 2014-06-20 at 09:17 +0200, Raphael Hertzog wrote: > Why not switch it to something more dynamic ? Sounds good... > Make the package an empty shell with symlinks pointing to > /var/lib/debian-keyring/, add a cron job that rsyncs the keyring > to that directory. I've just thought about th

Bug#752189: ITP: mariadb-client-lgpl -- LGPL version of MariaDB client libraries

2014-06-20 Thread Daniel Schepler
Package: wnpp Severity: wishlist Owner: Daniel Schepler * Package name: mariadb-client-lgpl Version : 2.0.0 Upstream Author : MariaDB Foundation * URL : https://mariadb.org/ * License : LGPL 2.1 Programming Lang: C Description : LGPL version of MariaDB

Re: improving downloader packages (was: Re: holes in secure apt)

2014-06-20 Thread Christoph Anton Mitterer
On Thu, 2014-06-19 at 21:25 -0500, Gunnar Wolf wrote: > Thanks for bringing this topic up. I'm snipping your very detailed > implementation proposal, which does not sound like it was written at > 4AM at all ;-) ;-) > I do feel the keyring-maint package is a leftover from days long > gone. Nowada

Re: holes in secure apt

2014-06-20 Thread Christoph Anton Mitterer
On Tue, 2014-06-17 at 10:48 +0200, David Kalnischkies wrote: > On Mon, Jun 16, 2014 at 12:04:51PM +0200, Thorsten Glaser wrote: > > Erm, no? You can just cache a working Sources file and exchange > > the paragraph you are interested in. That’s something that would > > be easy in a CGI written in s

Re: New project goal: Get rid of Berkeley DB (post jessie)

2014-06-20 Thread Neil McGovern
On Sat, Jun 21, 2014 at 12:49:52AM +0800, Thomas Goirand wrote: > So, do I understand well that it's your view that just linking with > AGPLv3 make it mandatory to re-license using AGPLv3? Is there such a > clause in the AGPLv3 license? > No, it's required to re-licence it to AGPLv3, or an AGPLv3

Re: New project goal: Get rid of Berkeley DB (post jessie)

2014-06-20 Thread Thomas Goirand
On 06/20/2014 05:57 PM, Ondřej Surý wrote: > Please let's not have this discussion again. There are more problems > with Berkeley DB than just relicensing. > > On Fri, Jun 20, 2014, at 09:47, Thomas Goirand wrote: >> Respectfully, this is only your own opinion. Maybe I'm wrong, but I >> myself fai

Bug#752181: ITP: python-evtx -- pure Python parser for recent Windows Event Log files

2014-06-20 Thread Hilko Bengen
Package: wnpp Owner: Hilko Bengen Severity: wishlist * Package name: python-evtx Version : 0.3.1 Upstream Author : Willi Ballenthin * URL or Web page : http://www.williballenthin.com/evtx/ * License : Apache-2.0 Description : pure Python parser for recent Windows Eve

Bug#752172: ITP: python-loofah -- debile helper to rebuild a set of existing packages

2014-06-20 Thread Clément Schreiner
Package: wnpp Severity: wishlist Owner: "Clément Schreiner" * Package name: python-loofah Version : 0.1 Upstream Author : Paul Tagliamonte, Sylvestre Ledru, Clément Schreiner * URL : https://github.com/paultag/loofah * License : Expat Programming Lang: Python

Re: New project goal: Get rid of Berkeley DB (post jessie)

2014-06-20 Thread Clint Adams
On Fri, Jun 20, 2014 at 01:36:35PM +0100, Simon McVittie wrote: > For (1), the AGPL is nowhere near as widely used as the GPL, and we > don't have community norms for how to interpret it and how to comply > with it. I don't intend my deployment of ikiwiki-hosting for myself, > friends and family to

Re: Future of Developer's Reference

2014-06-20 Thread Clint Adams
On Thu, Jun 19, 2014 at 11:08:29PM +0200, Tshepang Lekhonkhobe wrote: > Does 'bullshit' mean that the content is of low quality, or are there > other issues? I'm not sure how to answer this without violating the CoC. -- To UNSUBSCRIBE, email to debian-devel-requ...@lists.debian.org with a subje

Re: New project goal: Get rid of Berkeley DB (post jessie)

2014-06-20 Thread Simon McVittie
On 20/06/14 08:47, Thomas Goirand wrote: > Respectfully, this is only your own opinion. Maybe I'm wrong, but I > myself fail to see why the AGPLv3 is a problem. And I don't understand > why you wrote that "the AGPLv3 is not very friendly to downstream > projects". IMO it is only unfriendly with pro

Bug#752169: ITP: python-ricky -- tool for rebuilding packages using the Debile infrastructure

2014-06-20 Thread Clément Schreiner
Package: wnpp Severity: wishlist Owner: "Clément Schreiner" * Package name: python-ricky Version : 0.1 Upstream Author : Paul Tagliamonte, Sylvestre Ledru, Léo Cavaillé, Clément Schreiner * URL : https://github.com/paultag/ricky * License : Expat Programming

Bug#752164: ITP: r-cran-truncnorm -- GNU R truncated normal distribution

2014-06-20 Thread Andreas Tille
Package: wnpp Severity: wishlist Owner: Andreas Tille * Package name: r-cran-truncnorm Version : 1.0-7 Upstream Author : Olaf Mersmann * URL : http://cran.r-project.org/web/packages/truncnorm/ * License : GPL Programming Lang: R Description : GNU R tr

Re: New project goal: Get rid of Berkeley DB (post jessie)

2014-06-20 Thread Ondřej Surý
Please let's not have this discussion again. There are more problems with Berkeley DB than just relicensing. On Fri, Jun 20, 2014, at 09:47, Thomas Goirand wrote: > Respectfully, this is only your own opinion. Maybe I'm wrong, but I > myself fail to see why the AGPLv3 is a problem. And I don't und

Bug#752158: ITP: idlestat -- measures CPU time in idle and operating states

2014-06-20 Thread Colin Ian King
Package: wnpp Severity: wishlist Owner: Colin Ian King * Package name: idlestat Version : 0.3 Upstream Author : Daniel Lezcano * URL : https://wiki.linaro.org/WorkingGroups/PowerManagement/Resources/Tools/Idlestat * License : GPL-2+ Programming Lang: C De

Bug#752153: ITP: r-cran-genabel.data -- data package for genome-wide SNP association analysis

2014-06-20 Thread Andreas Tille
Package: wnpp Severity: wishlist Owner: Andreas Tille * Package name: r-cran-genabel.data Version : 1.0.0 Upstream Author : Maksim Struchalin * URL : http://cran.at.r-project.org/web/packages/GenABEL.data/ * License : GPL Programming Lang: R Description

Re: New project goal: Get rid of Berkeley DB (post jessie)

2014-06-20 Thread Thomas Goirand
On 06/19/2014 06:42 PM, Ondřej Surý wrote: > On Thu, Jun 19, 2014, at 12:33, Svante Signell wrote: >> On Thu, 2014-06-19 at 11:38 +0200, Ondřej Surý wrote: >>> Hi, >>> >>> >>> >>> my view is that Berkeley DB is dead since Oracle relicenced it to AGPL3; >> >> What is wrong with that license, and wh

Re: improving downloader packages (was: Re: holes in secure apt)

2014-06-20 Thread Raphael Hertzog
Hi, On Thu, 19 Jun 2014, Gunnar Wolf wrote: > FWIW, I was thinking about including the possible disappearance as one > of the points to talk about in the DebConf BoF we proposed regarding > keyring-maint. Why not switch it to something more dynamic ? Make the package an empty shell with symlinks