Live data from Hacker News

I Love Arch, but GNU Guix Is My New Distro

boilingsteam.com

281–290 of 318 posts

Re: I Love Arch, but GNU Guix Is My New Distro

#281
post #111

Earlier quoted context omitted.

Lobbing a charge like "Arbitrary religious dogma" is pretty much the opposite of a reasoned look at what the goals are here. I find the approach interesting. The goal of the Free Software folk was never primarily to "provide the best information to the end user," it is to "preserve software freedom." Guix looks like a possible technical path to do that. Will it work? Will it cause harm? I don't know yet. Either way,…

Cited from the article: To respect these principles the Guix project (and others) asks to not discuss non-free software, hardware support, or related matters on official channels. These questions and non-free packages are best left to any number of other venues. Guix does not actively hamper a user’s ability to load non-free software or firmware (see freedom 0), but will not support this in any official capacity. Tha…

I don't think that's what is being "said" at all.

This is diplomacy. This is exactly the correct way to act when you are diametrically opposed to something that is widely used, popular, and prevalent -- when you hate something; but understand that other people don't and you're going to have win them over.

Re: I Love Arch, but GNU Guix Is My New Distro

#282
post #280

Earlier quoted context omitted.

>The FSF totally acts as a religion. The church of his Gnusance St. Ignutiutus. And just like religions it pretends to hold an ethical position while making compromises for practical reasons. so is FSF dogmatic or is it practical? surely they cant be both

It's definitely both -- it's just that the dogma is broad, and they appear to very carefully and intelligently choose battles. The dogma is "long term software freedom." This includes occasionally accepting that there are battles not worth fighting (or better yet, fighting strategically.) A really simple example is GPL violations. Pure dogma would require that they try to fight a whole lot of them, since they occur a…

then you must disagree with alexvoda who said that FSF "pretends to hold an ethical position"?

to clarify my previous post, i was using the term dogmatic in the context of some people claiming that FSF is a cult

Re: I Love Arch, but GNU Guix Is My New Distro

#283

Earlier quoted context omitted.

> If you are using off the shelf hard cores in silicon, you need to trust the vendor if i dont have options for alternatives, i think its completely rational to use something without trusting it. i would say that this should be a default attitude

Sandboxing and fencing off untrusted parts is fine. I find the approach of Librem 5 understandable. However the distinction between blob on chip flash and blob on system storage is nonsensical to me. I would much rather have a sandboxed untrusted part I can update rather than a sandboxed untrusted part that I can not update. Unfortunately I have not seen anyone actually give a reason why the line should be drawn ther…

>Unfortunately I have not seen anyone actually give a reason why the line should be drawn there instead of closed source blobs are not ok period

this makes it sound like FSF supports these blobs. how i understood the situation is that they tolerate them until an alternative presents itself. this is a valid position to take and does not make them hypocrites/cult/religion etc

Re: I Love Arch, but GNU Guix Is My New Distro

#284

Guix is excellent, however, I use CUDA heavily in my work, and it is hard to plug nVidia drivers into Guix.

Can you find out if these support your graphics card? If they do, you can just add a channel pointing to this git repo.

https://gitlab.inria.fr/guix-hpc/guix-hpc-non-free/-/tree/ma...

How to add a channel https://guix.gnu.org/manual/en/html_node/Using-a-Custom-Guix...

Re: I Love Arch, but GNU Guix Is My New Distro

#285
post #216

As much as I love lisp and hate the Nix expression language, I'm interested in actually getting things done more than I am in preserving software freedom, so I'm on NixOS.

Guix makes it very easy to add whatever non-free software you want via channels. You just won't get it with the default installation.

I suppose I (perhaps unfairly) pre-judged the Guix community based off of past experiences with libre-only distros. I have memories of listserv threads and IRC conversations where it felt like people were trying to catch people daring to run proprietary software on their distro just so they could shut down the conversation with "This distro only supports running Free Software"

Re: I Love Arch, but GNU Guix Is My New Distro

#286
post #135

Earlier quoted context omitted.

Sorry, but you are wrong. GNU people won't run nonfree JS at all. LibreJS is a good example in order to kill any potential Spectre/Meltdown attack. There is no attack when no code is being run.

> There is no attack when no code is being run. https://9to5mac.com/2021/03/11/browser-based-attack-affects-... Turns out you don't need Turing completeness to perform microarchitectural side channel attacks. This is yet another way in which the "all my software is free, therefore I am safe from attacks" fallacy breaks down. Nevermind that, as pointed out by other replies, LibreJS provides zero security. It relies on…

Dillo has a nice CSS-less rendering. Also, Links+.

I am still safe.

Re: I Love Arch, but GNU Guix Is My New Distro

#287
post #280

Earlier quoted context omitted.

It's definitely both -- it's just that the dogma is broad, and they appear to very carefully and intelligently choose battles. The dogma is "long term software freedom." This includes occasionally accepting that there are battles not worth fighting (or better yet, fighting strategically.) A really simple example is GPL violations. Pure dogma would require that they try to fight a whole lot of them, since they occur a…

then you must disagree with alexvoda who said that FSF "pretends to hold an ethical position"? to clarify my previous post, i was using the term dogmatic in the context of some people claiming that FSF is a cult

To go big picture, I think all of this is rooted in the fact that "capitalism as practiced" has addled our brains into thinking that there can only be two kinds of organizations, companies that go for profit at all cost, and pure-of-heart non-profits that must be on some monk-like religious stuff.

What it can't conceive of is an organization with big picture goals that aren't "making a profit" that require strategy and even "real life experimentation." That's what's happening here; y'all are just confused because the FSF feels like "religion" because it's not going for profits, but somewhat acting like a for-profit, in that it's picking and choosing battles.

Re: I Love Arch, but GNU Guix Is My New Distro

#288
post #269

Earlier quoted context omitted.

The problem is the endorsement of linux-libre, which goes beyond deblobbing into actively censoring messages. I'm sure Guix allows users to choose (it has to, thanks to Freedom 0, as you say), but by choosing a kernel by default that chooses to withhold information from its users, it is encouraging decreasing user knowledge. That is something that people should be aware of, and honestly, something that should be cons…

This is completely obtuse. Why isn’t your anger at the Guix or Linux-libre maintainers’ supposed withholding of information (‘censorship’) directed instead at publishers of closed-source, unauditable binary blobs, which constitute a fundamentally greater security risk than any auditable code repository ever could? How does it even make sense for Linux-libre to publish notifications about available binary blobs of any…

You're ignoring the crux if the issue. This isn't about running proprietary microcode or not. All x86 Guix users are running proprietary microcode. Period. This is a fact, whether they know about it or not. It's not optional. Would it be great if they didn't have to? Sure. But that's not the world we live in.

This is about withholding information about an update to the proprietary microcode they are already running. There is absolutely no reason not to offer users this choice, given they're stuck running the ROM blob to begin with. The only reason the FSF and Linux-libre do this is because they want users to feel better by not knowing about the blob they're already running. There is no freedom gained, only the illusion of freedom. Users don't know what their ROM microcode does just as much as they don't know what the update does. The only thing we know is it fixes a bug.

I believe a world where all software, firmware, and hardware is free would be ideal. I also know that is not the world we live in, and so I believe in empowering users with the information about what options they have, what the security/freedom/privacy/etc tradeoffs are, and letting them make their own choices. The FSF's push for restricting information so people believe they are not running any nonfree code is diametrically opposed to my views for this reason. I believe having the illusion of freedom is harmful to the cause for software freedom, as it obfuscates the reality of the current state of affairs. Every single die-hard FSF fanboy needs to learn about the 27 blobs running in little ROMs inside their computer, so they stop believing they live in a fake freedom utopia and come to terms with the reality we live in. Maybe then we'll have even more people pushing for firmware freedom.

I'm not even saying Guix should ship the update. But actively censoring information about the existence of the update? That's just ridiculous. Your users are already running the blob. Stop trying to pretend they aren't and tell them it's broken already. How is it better when users are stuck running broken proprietary software when a fix is available because you refuse to inform them about it? That's completely irrational.

Incidentally, this is a falsehood:

> closed-source, unauditable binary blobs, which constitute a fundamentally greater security risk than any auditable code repository ever could

This kind of absolutist view is another problem with this school of thought. Blobs can be in a position where, by the nature of their access or lack thereof to the rest of the system, they pose minimal security risk even if presumed completely evil. This is evidently a much lower risk than, say, low quality open source code in a position of extreme privilege with a large attack surface. Auditability doesn't mean things get audited or all bugs fixed. I have no problem trusting that a blob in a harmless I/O microcontroller poses little to no security risk to me over, say, certain open source cryptography/key storage implementations I've seen which raise a million red flags. Context matters, and the FSF's refusal to consider any context or nuance is also hurting users by not empowering them to make the decisions that are the best for them.

Re: I Love Arch, but GNU Guix Is My New Distro

#289
post #272

Earlier quoted context omitted.

There is no reason to trust IBM not to include a silicon backdoor in POWER9 more than Intel not to include a silicon or microcode backdoor in their x86 chips. TALOS is a lot freer than most designs, but you still need to trust every manufacturer whose silicon went into that motherboard.

>There is no reason to trust IBM not to include a silicon backdoor Yeah ok now we are in the religion side of things, since you cannot check the silicon...well i stop here, not worth my time. BTW: The power microcode is opensource.

You can backdoor silicon just as well as you can backdoor software or microcode. Why do you only care about trusting the latter?

Re: I Love Arch, but GNU Guix Is My New Distro

#290

Earlier quoted context omitted.

Sandboxing and fencing off untrusted parts is fine. I find the approach of Librem 5 understandable. However the distinction between blob on chip flash and blob on system storage is nonsensical to me. I would much rather have a sandboxed untrusted part I can update rather than a sandboxed untrusted part that I can not update. Unfortunately I have not seen anyone actually give a reason why the line should be drawn ther…

>Unfortunately I have not seen anyone actually give a reason why the line should be drawn there instead of closed source blobs are not ok period this makes it sound like FSF supports these blobs. how i understood the situation is that they tolerate them until an alternative presents itself. this is a valid position to take and does not make them hypocrites/cult/religion etc

They are literally endorsing Bluetooth dongles with half a megabyte of proprietary ROM as "respecting your freedom". That goes a little beyond "tolerating", don't you think?
Post reply on HN