Live data from Hacker News

I Love Arch, but GNU Guix Is My New Distro

boilingsteam.com

231–240 of 318 posts

Re: I Love Arch, but GNU Guix Is My New Distro

#231
post #99

Earlier quoted context omitted.

God doesn't exist, that doesn't prevent him of being. The quest for freedom is, of course, an idealistic one. The important thing is that, in their fight to promote freedom, they meet obstacles. Those friction points reveal the lack of freedom. And so, although they don't reach freedom, they actually show that freedom is limited. IOW, refusing the statu quo is one of the way to change it. You should look at history a…

> IOW, refusing the statu quo is one of the way to change it. And yet they aren't changing it. The FSF has had exactly zero success in changing the direction the world is moving in with regards to firmware and deep proprietary integration. In fact, they've done very little for freedom in the past 10-20 years; most of the real breakthroughs have come from much more pragmatic people, such as those developing reverse en…

>In fact, they've done very little for freedom in the past 10-20 years; most of the real breakthroughs have come from much more pragmatic people, such as those developing reverse engineered open source drivers for complex hardware like GPUs.

Whose efforts get completely circumvented through employment of cryptographic firmware signing, which gate keeps necessary functionality out of said pragmatist's reach.

Re: I Love Arch, but GNU Guix Is My New Distro

#232

Earlier quoted context omitted.

i am not affiliated with FSF in any way. yet it seems to me that there are plenty of people arguing against them in very bad faith. here is the full excerpt in question: BEGIN >CPUs supported: >AMD Opteron 6100 series (Fam10h. No IOMMU support. Not recommended - old. View errata datasheet here: http://support.amd.com/TechDocs/41322_10h_Rev_Gd.pdf ) >AMD Opteron 6200 series (Fam15h, with full IOMMU support in libreboo…

If you are referring to me, I don't see how my excerpt is incomplete or could be seen as bad faith. Libreboot is steering people away from 6300 processors because using them requires explicitly loading a proprietary blob, while encouraging the use of 6200 processors that have an analogous blob baked in at the factory. The real difference is that the former makes you more aware of the compromise.

reading the full excerpt seems to put the reason for rejecting 6300 onto Errata 734 and it was strange to me that this wasnt addressed in your post

however i wasnt referring to you specifically as arguing in bad faith but that seems to be the attitude of some very vocal people here. i included the full excerpt in case the point is relevant. i am not an expert in this field

does the issue in Erata 734 apply to 6200?

Re: I Love Arch, but GNU Guix Is My New Distro

#233
post #199

Earlier quoted context omitted.

One of the nice things about the FSF's free software principles is that if you disagree with how they think you should use their software, they're not going to stop you. Nonguix[1] provides solid non-free support if that's what you want. In fact it has a helpful section on microcode updates. The FSF even condones non-free software (in a rather dorky way) for people whose machines require it[2]. I understand the FSF's…

I fully believe in software freedom (including favoring the GPL), and am trying to push it forward with this argument. I just see using a "6300 with microcode 2019-12-18" as the exact same compromise as using a "6200 with microcode 2011-11-14", regardless that the first blob was loaded at runtime while the second blob was loaded at the factory. Neither one lets me audit or modify my processor. There aren't many perfo…

It sounds like we have very similar beliefs. I think the FSF should acknowledge that microcode updates and such are odious but tolerable moral compromises and that we should continue to work for a future where we have complete freedom to modify, repair, and otherwise use our machines as we see fit.

However, for fun, I'm going to do my best to steelman the FSF position: The use of non-free software when no free alternative exists is tolerable. The material difference between firmware that comes with the hardware or microcode that comes with the CPU versus a downloadable update is that the update is voluntary, and thus involves a willful violation of the principle of freedom. By doing so one becomes actively complicit in the erosion of freedom.

I also agree that they shouldn't be jerks on mailing lists and IRC, but have some empathy for persons that aren't so fortunate that they can eschew all non-free software.

Re: I Love Arch, but GNU Guix Is My New Distro

#234

Earlier quoted context omitted.

>To them, all visible blobs are equally bad, regardless of whether one can completely compromise your system and another one is completely harmless and requires no trust. For a company that values software freedom above all else this is completely fine. If they are called Secure Software Foundation then your arguments would hold more weight. For example, I really doubt that FSF would claim that GNU Guix is more secur…

Security is part of protecting your freedom from being compromised. I read this entire thread and wholeheartedly agree with marcan_42. FSF's position to draw a line where none exists is foolish wishful thinking and potentially dangerous. I prefer knowing that I live in a world where COMPLETE software freedom is close to unachievable and it (COMPLETE software freedom) is a worthy goal to strive for compared to deceivi…

>I read this entire thread and wholeheartedly agree with marcan_42

and you are free to do that and i would not say that you are a part of marcan-worshipping-cult or following some dogma

>deceiving myself into believing it has been achieved by ignoring anything below a certain level

if you are stating that this is what FSF believes then you are in fact spreading a falsehood and fud. this is what marcan has been doing regarding FSF the whole time during this engagement

>Just because I choose to amputate my ability to update firmware does not mean a malicious party might not be able to do so. Anyone with physical access to hardware will still have that ability by using extra hardware. Handwaving the firmware away does not work against an evil maid attack.

Unless FSF is claiming that GNU Guix is secure by design, or is free from such attacks, this is just a strawman argument

Re: I Love Arch, but GNU Guix Is My New Distro

#235

Earlier quoted context omitted.

If you are referring to me, I don't see how my excerpt is incomplete or could be seen as bad faith. Libreboot is steering people away from 6300 processors because using them requires explicitly loading a proprietary blob, while encouraging the use of 6200 processors that have an analogous blob baked in at the factory. The real difference is that the former makes you more aware of the compromise.

reading the full excerpt seems to put the reason for rejecting 6300 onto Errata 734 and it was strange to me that this wasnt addressed in your post however i wasnt referring to you specifically as arguing in bad faith but that seems to be the attitude of some very vocal people here. i included the full excerpt in case the point is relevant. i am not an expert in this field does the issue in Erata 734 apply to 6200?

> reading the full excerpt seems to put the reason for rejecting 6300 onto Errata 734

Well there are two reasons. The first is Errata 734, and the second is that the fix for Errata 734 requires loading different microcode than what was baked into the processor at manufacturing time ("6300 series CPUs have buggy microcode built-in, and libreboot recommends avoiding the updates"). I didn't mention Errata 734, because I'm focused on the second reason.

Working back from their reasoning, Errata 734 seemingly does not apply to the 6200 series.

Re: I Love Arch, but GNU Guix Is My New Distro

#236

Earlier quoted context omitted.

but security is associated with free and open source software. i think this is a common position of a vast majority of security experts. to make your claim that FSF deceives or misleads people you need to do a LOT more. for example, can you provide an example where someone claims that GNU Guix is secure by design[0] i think that taking a position that free software supports security and also that free software princi…

The factors that actually impact the upper boundary of achivable security are availability of source code (open or not) and reproducible builds. The 4 freedoms do not actually affect any aspect of security, they are orthogonal. Also, just because the 2 factors above impact the upper boundary of achievable security does not mean an open source software is automatically more secure. It is conceivable for 2 comparable p…

>does not mean an open source software is automatically more secure

well my point is that FSF never anywhere claimed otherwise. if they did THAT would be wrong and irresponsible

>It is conceivable for 2 comparable pieces of software to exist one open source and the other closed source and for the closed source one to be more secure.

sure. well a simple example is that security by obscurity is a valid concept in a right environment

Re: I Love Arch, but GNU Guix Is My New Distro

#237

Earlier quoted context omitted.

Security is part of protecting your freedom from being compromised. I read this entire thread and wholeheartedly agree with marcan_42. FSF's position to draw a line where none exists is foolish wishful thinking and potentially dangerous. I prefer knowing that I live in a world where COMPLETE software freedom is close to unachievable and it (COMPLETE software freedom) is a worthy goal to strive for compared to deceivi…

>I read this entire thread and wholeheartedly agree with marcan_42 and you are free to do that and i would not say that you are a part of marcan-worshipping-cult or following some dogma >deceiving myself into believing it has been achieved by ignoring anything below a certain level if you are stating that this is what FSF believes then you are in fact spreading a falsehood and fud. this is what marcan has been doing…

The FSF is deceiving themselves and others by believing that just because a user no longer has the ability to update firmware on a device, that device is acually no longer running non-free code.

I really do not understand what is so hard to understand that from a free software POV there is no distinction between a chip loading a blob from system storage and a chip loading a blob from it's own tiny updatable flash. Both load a non-free blob. Neither fully respects your freedom. Drawing the line of Respects Your Freedom TM between those 2 is stupid and deceptive.

The users ability to update firmware is also the ability to revert firmware changes (to a old trusted even if closed source version) made by a malicious party. Users do not gain any freedom by giving up that ability. They loose freedom.

Being able to choose between MS Office and Lotus and Star Office and WPS Office (1) gives the user more freedom compared to being stuck with just MS Office (2), even if none of those respect your freedom. Being able to also choose Libre Office (3) is obviously better. But 1 is still obviously better than 2. The existance or absence of 3 does not change that.

With regards to firmware, the FSF believes that 2 is better than 1. That is stupid. How do you not see that?

It is a valid form of protest but Respects Your Freedom TM certified hardware does not truuuuly respect your freedom.

This is harmful because the goal should be hardware with FLOSS firmware with reproducible builds and with the option for the user to add their own signing keys, NOT unupdatable (by the user) closed source proprietary firmware.

Re: I Love Arch, but GNU Guix Is My New Distro

#238

Earlier quoted context omitted.

If you are referring to me, I don't see how my excerpt is incomplete or could be seen as bad faith. Libreboot is steering people away from 6300 processors because using them requires explicitly loading a proprietary blob, while encouraging the use of 6200 processors that have an analogous blob baked in at the factory. The real difference is that the former makes you more aware of the compromise.

reading the full excerpt seems to put the reason for rejecting 6300 onto Errata 734 and it was strange to me that this wasnt addressed in your post however i wasnt referring to you specifically as arguing in bad faith but that seems to be the attitude of some very vocal people here. i included the full excerpt in case the point is relevant. i am not an expert in this field does the issue in Erata 734 apply to 6200?

mindslight, i cant reply to you directly so i will do it like this. thank you for clarifying about Erata 734. if Erata 734 applied to 6200 then libreboots logic would make no sense

i take no issue about with critically discussing someones logic. fud and attacks are annoying and dont contribute to a healthy discussion

Re: I Love Arch, but GNU Guix Is My New Distro

#239

Earlier quoted context omitted.

Security is part of protecting your freedom from being compromised. I read this entire thread and wholeheartedly agree with marcan_42. FSF's position to draw a line where none exists is foolish wishful thinking and potentially dangerous. I prefer knowing that I live in a world where COMPLETE software freedom is close to unachievable and it (COMPLETE software freedom) is a worthy goal to strive for compared to deceivi…

>I read this entire thread and wholeheartedly agree with marcan_42 and you are free to do that and i would not say that you are a part of marcan-worshipping-cult or following some dogma >deceiving myself into believing it has been achieved by ignoring anything below a certain level if you are stating that this is what FSF believes then you are in fact spreading a falsehood and fud. this is what marcan has been doing…

[deleted]

Re: I Love Arch, but GNU Guix Is My New Distro

#240
post #137
post #19

Earlier quoted context omitted.

What about number of packages available? Does guix have something comparable to Nix Flakes?

Guix has lots of packages in the default channel, and you can add any odd git repo as another channel providing extra software. There are quite a few popular channels, such as non-guix (with things like vanilla Linux), guix-science, guix-past, etc. As a maintainer of R packages in Guix I'd also like to point out that many R packages in Nix actually need more work to build them, so the number of packages in Nix is rat…

Currently in nixpkgs ~3% of rPackages fail to build.
Post reply on HN