Comment 4 for bug 1706471

Revision history for this message
Seth Arnold (seth-arnold) wrote :

I'm not saying it's not useful. The point is that the library that we're
using for Exif metadata is unsuited for use on a modern desktop operating
system or server connected to the Internet.

The maintainer doesn't want to put in the work to take it from a fun
hobby to a production-grade tool. I can understand that, and I'm even
sympathetic that it was used more widely than it should have been. That's
not his fault.

But we have millions of users who expect us to protect them against
drive-by downloads that own their desktops and server administrators
who expect to use the tools we provide to build safe services for their
users in turn.

Ideally shotwell would be able to degrade service gracefully until someone
cares enough to write a safe Exif library. Less ideal would be to demote
shotwell until this is addressed.

Thanks