You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@qpid.apache.org by Alan Conway <ac...@redhat.com> on 2015/05/06 17:31:12 UTC

Re: Configuration for security (irrelevant musings)

On Wed, 2015-05-06 at 11:09 -0400, Andrew Stitcher wrote:
> On Wed, 2015-05-06 at 10:28 -0400, Alan Conway wrote:

> I agree with this restatement of your position 100% - user configurable
> settings are evil.

I like to think that user configurable settings are an admission of
failure by the developer. "I can't figure out what the code should do,
so I'll make the user tell me." Rarely does the developer stop to wonder
"If I, with access to all the code and run-time state of the program,
can't figure it out, how is the user going to?"




---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscribe@qpid.apache.org
For additional commands, e-mail: dev-help@qpid.apache.org