Re: Re-thinking Debian membership

On Fri, Oct 24, 2008 at 03:53:46PM +0300, Lars Wirzenius wrote:
> pe, 2008-10-24 kello 12:18 +0200, Peter Palfrader kirjoitti:
> > On Fri, 24 Oct 2008, Lars Wirzenius wrote:
> > > * The keyrings shall be maintained in a way that allows any
> > >   member to change them,
> The rationale is simple: to avoid concentration of power into the
> hands of the few, and keep it in the hands of everyone. Since I
> believe the decision on someone's membership should be collectively
> in the hands of all the members, I don't think the task of editing a
> keyring should be restricted to one or a couple of people.

That sounds a bit too extreme to me. [1]

Trust don't scale very well, and while I agree with the general
principle of diminishing concentration of powers, I would be against
such a proposal.

A scenario I want to avoid for example is that newcomers can alter the
keyring adding tens of "friends". Such a possibility would imply that
if Debian as a project fails *once* in checking IDs and motivations
for *a single* newcomer, than that newcomer can screw us badly adding
a whole lot of people.  I presume the range of nasty scenarios
starting from this one is quite big.

The solution to the past problems we had with keyring management is
having a bigger keyring team (3/4 people?), but not that big.

More generally, the solution to concentration of powers is making sure
that the same people do not play too many roles in "core" teams
(ideally, max 1), because that gets rid of "communications to self",
which are always hidden to the rest of the project.

My 0.02€.

[1] I'm also convinced this feeling reflects those of most of us, but
    of course there is no intention of trying being authoritative.

Stefano Zacchiroli
zack@{upsilon.cc,pps.jussieu.fr,debian.org} -<>- http://upsilon.cc/zack/
Dietro un grande uomo c'è sempre /oo\ All one has to do is hit the right
uno zaino        -- A.Bergonzoni \__/ keys at the right time -- J.S.Bach

