Little essay

I don't know why everyone bother about that autodownload should be off by default. Can I ask who here using autodownload off because he want it off? There is many software around and nobody care about "autodownload". When you compile your own qvm - you inspecting all 200 000 lines of code (of how many) if there is something bad/backdoor/bug? Of course you not. You will compile it, using it and you feel safe. You will take precompiled tremded and feel safe. You will use tremfusion, mg client and many more things and feel safe. But wait - autodownload is on? It's unsafe (anyway you will put autodownload on manually - so no point here)!
I compiled Mangos - World of Warcraft emulator. 500 000 lines of source code. Is there any backdoor? Is there autodownload on? Hell I don't know and I don't care. I created new user on linux for mangos, new access to mysql and end of story. Do what you want mangos.
If autodownload is bad, if it is so bad thing, so big security hole, then whole tremulous/qvm potentionaly is. And if you believe in this and you install this on your company computer, then it is your fault. Like any other software.
I think that 90% tremulous players will reinstal his OS every month, they even don't know about autodownload and they have more viruses in computer than regular software. They are disconnected from server due to autodownload off. Even if they will download something bad trough autodownload on, nothing extra happen. They expecting next reinstall soon.
9% players can turn autodownload on, like me.
1% never turn autodownload on because they want it off (this is only reserve)
It's same like when you want to try some modded server, you need to have autodownload on and you cannot inspect source codes, because you downloading qvm. Even on MG servers. Do you think you can trust MG? If you are so scared by autodownload on, you can trust NODOBY. For persons like that is tremulous bad choice like 99% other software on the world.
I agree, window with "do you want download this?" before downloading is good thing. But in reality it will solve nothing about security. Only 90% will be not disconnected, 9% will turn it on with more friendly way and 1% without change. Same with default autodownload on - 90% will be not disconnected, 9% not need turn anything on, 1% will never download that client.
