4 ms·
The Linux Kernel development process is old-fashioned and there are lot of particular processes and conventions which make submitting a patch difficult. Also,
by muricula 5y ago
The Linux Kernel development process is old-fashioned and there are lot of particular processes and conventions which make submitting a patch difficult. Also, if you use gmail with mutt to submit a patch, you have to change your email preferences to make gmail less secure[1]. It would be nice to have a friendlier way to contribute to the kernel, and a GitHub bridge seems like a good idea.
[1]: https://medium.com/@crhenr/submitting-your-first-patch-to-the-linux-kernel-e81d2541fac6 https://medium.com/@crhenr/submitting-your-first-patch-to-th...
- andrewchambers 5y agoThis is google imposed FUD to exercise control over users. They didn't need to design like that, but they want to make it hard to use things that are not google controlled.
- judge2020 5y agoIMAP/SMTP access with only your password is extremely insecure. Especially as most non-techie humans don’t use a password manager or even a strong password.
- andrewchambers 5y agoYes, but google could easily support per application passwords. They just don't want to... in fact, they used to and removed it. They could also invest in other ways to make existing workflows work securely instead of imposing their own ones.
- judge2020 5y agoSounds like oauth, which is an open standard.
- jeroenhd 5y agoOAuth is far from standard in email. Google is the only company I know of that uses it for email. Per-application passwords are static passwords you generate for special applications. This way, the standard IMAP/SMTP logins will work, but a leaked password does not expose your entire Google account, only the email part. It also allows revocation of one application without re-entering your password on every device. It works flawlessly for many services, and Google supports/supported it as well. Using it just flags/flagged your account as "insecure" for some reason. Probably because they want you to use their propietary OAuth flow where they have more control over your software.
- g_p 5y agoMicrosoft, Yahoo (i.e. OATH) and others also use it, but it has limited adoption beyond the "big giants" of email. https://docs.microsoft.com/en-us/exchange/client-developer/legacy-protocols/how-to-authenticate-an-imap-pop-smtp-application-by-using-oauth https://docs.microsoft.com/en-us/exchange/client-developer/l... In a way, server providers prefer it as (in theory) users' long term credentials don't end up stored locally in plain text. A revocable per application token is used instead, and they can trace that back to a specific application or developer registration. That it trains users it's ok to enter passwords in bespoke web views using abnormal or no clear URL view is a big issue though in my opinion - I've never liked flows that encourage entering passwords into web browsers you didn't open yourself, let alone ones provided by third party software, which can capture anything happening within the app itself.
- oauea 5y agoDid they remove app passwords? This page is still there https://support.google.com/accounts/answer/185833?hl=en https://support.google.com/accounts/answer/185833?hl=en
- andrewchambers 5y agoFor me it originally worked flawlessly. Then I tried to use it again and lots of the menus the support pages referenced were no longer present. It was an endless cycle of broken links and features being hidden deeper and deeper in menus. If that haven't removed it (I thought they had), it kind of made the intention clear to me.
- arp242 5y agoThat's just Google doing their usual best at designing UIs and documenting things. It's like watching your 5-year old do their best "helping" doing housework. Cute, but not actually very helpful.
- turminal 5y agoWhy would you use mutt instead of git send-email?
- duskwuff 5y ago> Also, if you use gmail with mutt to submit a patch, you have to change your email preferences to make gmail less secure[1]. According to the article, this is because mutt uses IMAP, and needs to use password authentication (which might not even be accurate anymore). This has nothing to do with kernel development, beyond that some kernel developers like to use mutt as an email client.
- Dylan16807 5y ago> less secure[1] I see instructions around to make mutt use oauth, do they not work right? Like https://luxing.im/mutt-integration-with-gmail-using-oauth/ https://luxing.im/mutt-integration-with-gmail-using-oauth/