Re: fakeroot a solution for multi-architecture building?

[much I agree with deleted]

> where is the difference between having the pgp phase in kmem and having
> a sniffer program running as root, that will record the pass phrase when
> you build a package on your machine ? the security problem is the same
> in my opinion.

OK, yes, there isn't much difference.

All I was saying was that there _was_ something to worry about,
and fortunately you agree with me that we have to make the
build machines secure (whatever that takes).

Remember, I wrote fakeroot, and one major reason for me to put
so much time in it (and I do put a lot of time in fakeroot) is
precisely because I wanted to enable auto-building. So, I do
want it to go ahead. It's just that I do think we need to think
about making those build machines as secure as we can.

