Live data from Hacker News

I Love Arch, but GNU Guix Is My New Distro

boilingsteam.com

131–140 of 318 posts

Re: I Love Arch, but GNU Guix Is My New Distro

#131

Earlier quoted context omitted.

> "removes security warnings informing users that they need to update their CPU microcode" If you update your CPU microcode to something that can't be checked, you're already sacrificing security. EDIT: But yes, I understand people complaining that FSF rejects proprietary software but is OK with some forms of ROM which in turn may be very similar to "proprietary software you can't change". Well, I never asked their r…

Non sense. I trust my CPU provider or I wouldn’t have bought this CPU. I would much rather use an updated microcode than one known to be insecure. I wouldn’t check the microcode anyway and I don’t really trust the people who might more than the company providing my CPU. Sure it might contain code making me vulnerable to a state actor but that’s not a threat profile I care about.

If you have enough trust in proprietary software distributors to not care to use software that can't be checked, then you're probably not part of this discussion.

I don't check all the software I use myself. But I use open-source software with the peace of mind of someone who knows that the incentives to abuse me are simply not there and the fact that right now that are hundreds of people/bots checking it.

> Sure it might contain code making me vulnerable to a state actor but that’s not a threat profile I care about.

State actors are not the only threat. Think about arbitrarily disabled features, DRM, programmed obsolescence or simply not allowing anybody to improve/fix it after the device is abandoned by the manufacturer.

Re: I Love Arch, but GNU Guix Is My New Distro

#132

Just an anecdote, I accidentally broke something in my Guix system config but I couldn't figure out how to debug the scheme errors, and I had to reinstall

Yeah, that always seems to be the problem with embedded DSLs. Eventually you need to know your way around the host language.

Re: I Love Arch, but GNU Guix Is My New Distro

#133

Earlier quoted context omitted.

> "removes security warnings informing users that they need to update their CPU microcode" If you update your CPU microcode to something that can't be checked, you're already sacrificing security. EDIT: But yes, I understand people complaining that FSF rejects proprietary software but is OK with some forms of ROM which in turn may be very similar to "proprietary software you can't change". Well, I never asked their r…

Non sense. I trust my CPU provider or I wouldn’t have bought this CPU. I would much rather use an updated microcode than one known to be insecure. I wouldn’t check the microcode anyway and I don’t really trust the people who might more than the company providing my CPU. Sure it might contain code making me vulnerable to a state actor but that’s not a threat profile I care about.

I do not trust my CPU provider. Where do I find an alternative based exclusively on free software?

Re: I Love Arch, but GNU Guix Is My New Distro

#134

> Guix System is an advanced distribution of the GNU operating system. It uses the Linux-libre kernel It's worth pointing out that the linux-libre kernel is developed under the FSF doctrine that "binary blobs are bad unless you can't see them". This has been taken to its logical extreme here, where this Linux fork actively removes security warnings informing users that they need to update their CPU microcode , becaus…

> "removes security warnings informing users that they need to update their CPU microcode" If you update your CPU microcode to something that can't be checked, you're already sacrificing security. EDIT: But yes, I understand people complaining that FSF rejects proprietary software but is OK with some forms of ROM which in turn may be very similar to "proprietary software you can't change". Well, I never asked their r…

> If you update your CPU microcode to something that can't be checked, you're already sacrificing security.

You're not sacrificing security, you're making a tradeoff.

If I update my CPU microcode to something I can't check myself, I'm explicitly choosing to trust my CPU provider, under the assumption that the risk of a microcode-based attack from my CPU provider is smaller than the risk of a cpu bug-based attack by an unknown attacker.

Re: I Love Arch, but GNU Guix Is My New Distro

#135
post #74

Earlier quoted context omitted.

Well, for some people loading an arbitrary binary code without possibility to check what's inside it is a critical security issue as well.

Yeah. Then these geniuses get bitten by Spectre/Meltdown because they were too scared of running the microcode update. For real. I agree, if that's the position of Guix, I don't want it in my machine.

Sorry, but you are wrong. GNU people won't run nonfree JS at all.

LibreJS is a good example in order to kill any potential Spectre/Meltdown attack. There is no attack when no code is being run.

Re: I Love Arch, but GNU Guix Is My New Distro

#136

Earlier quoted context omitted.

> "removes security warnings informing users that they need to update their CPU microcode" If you update your CPU microcode to something that can't be checked, you're already sacrificing security. EDIT: But yes, I understand people complaining that FSF rejects proprietary software but is OK with some forms of ROM which in turn may be very similar to "proprietary software you can't change". Well, I never asked their r…

Non sense. I trust my CPU provider or I wouldn’t have bought this CPU. I would much rather use an updated microcode than one known to be insecure. I wouldn’t check the microcode anyway and I don’t really trust the people who might more than the company providing my CPU. Sure it might contain code making me vulnerable to a state actor but that’s not a threat profile I care about.

why is it nonsense? i think not trusting vendors that dont let you verify their product is quite sensible. note this is not paranoia to think that they are doing something malicious. its just as simple as dont trust strangers

Re: I Love Arch, but GNU Guix Is My New Distro

#137
post #19
post #11

Earlier quoted context omitted.

As a NixOS user who has (recently!) played with Guix, I don't think ‘battle testing’ is a great reason to prefer Nix. Guix has an excellent CLI and awesome docs. It's stable and plenty usable. All being in one, high-level language like Scheme makes it seem really easy to hack on, and I think that's part of why its CLI is so good already. Nix is faster, it supports macOS, and its package collection is much bigger beca…

What about number of packages available? Does guix have something comparable to Nix Flakes?

Guix has lots of packages in the default channel, and you can add any odd git repo as another channel providing extra software.

There are quite a few popular channels, such as non-guix (with things like vanilla Linux), guix-science, guix-past, etc.

As a maintainer of R packages in Guix I'd also like to point out that many R packages in Nix actually need more work to build them, so the number of packages in Nix is rather inflated. Guix also goes to great lengths to actually build things completely from source, such as Java packages, or to minify JavaScript from source files.

Re: I Love Arch, but GNU Guix Is My New Distro

#138

Earlier quoted context omitted.

Is the poster you’re replying to saying anything about the ease of parsing their policy? He doesn’t seem to be calling it confusing. Rather, he seems to be attacking the supposed (il)logic of its contentions and the resulting consequences. At the moment this back and forth feels like you’re talking past his actual point(s).

no. he is calling it deceptive, which is even stronger than confusing. his statement was: > They are deceiving people into believing they are not running proprietary software edit: as regards FSF's logic i am not informed enough to comment so i didnt. but the conversation (this thread) was definitely about deceptiveness

The FSF’s principles have always permitted the use of non-free software when it advances the goal of software freedom. GNU was initially built using non-free software.

Given the pejorative yet inaccurate references to “religion.” I can’t help but think some people are deeply disturbed by the very concept of moral principles and and cognitive dissonance is forcing them to hallucinate that the FSF doesn’t actually have principles but is instead a cult. Very odd.

Re: I Love Arch, but GNU Guix Is My New Distro

#139

Earlier quoted context omitted.

Non sense. I trust my CPU provider or I wouldn’t have bought this CPU. I would much rather use an updated microcode than one known to be insecure. I wouldn’t check the microcode anyway and I don’t really trust the people who might more than the company providing my CPU. Sure it might contain code making me vulnerable to a state actor but that’s not a threat profile I care about.

I do not trust my CPU provider. Where do I find an alternative based exclusively on free software?

https://www.raptorcs.com/TALOSII/

Re: I Love Arch, but GNU Guix Is My New Distro

#140

Earlier quoted context omitted.

Non sense. I trust my CPU provider or I wouldn’t have bought this CPU. I would much rather use an updated microcode than one known to be insecure. I wouldn’t check the microcode anyway and I don’t really trust the people who might more than the company providing my CPU. Sure it might contain code making me vulnerable to a state actor but that’s not a threat profile I care about.

I do not trust my CPU provider. Where do I find an alternative based exclusively on free software?

https://ryf.fsf.org/
Post reply on HN