Live data from Hacker News

I Love Arch, but GNU Guix Is My New Distro

boilingsteam.com

271–280 of 318 posts

Re: I Love Arch, but GNU Guix Is My New Distro

#271
post #173

Earlier quoted context omitted.

You are really wrong, a lot of services (specially news) work either without JS or have a libre alternative, such as Twitter/Nitter, or Reddit/Teddit.

I use NoScript and I find very few sites that are really broken if I don't enable JS.

Your and mine definition of very few sites must be different than.

Can you buy anything at all on the internet?

Re: I Love Arch, but GNU Guix Is My New Distro

#272
post #139

Earlier quoted context omitted.

https://www.raptorcs.com/TALOSII/

There is no reason to trust IBM not to include a silicon backdoor in POWER9 more than Intel not to include a silicon or microcode backdoor in their x86 chips. TALOS is a lot freer than most designs, but you still need to trust every manufacturer whose silicon went into that motherboard.

>There is no reason to trust IBM not to include a silicon backdoor

Yeah ok now we are in the religion side of things, since you cannot check the silicon...well i stop here, not worth my time.

BTW: The power microcode is opensource.

Re: I Love Arch, but GNU Guix Is My New Distro

#273
post #271

Earlier quoted context omitted.

I use NoScript and I find very few sites that are really broken if I don't enable JS.

Your and mine definition of very few sites must be different than. Can you buy anything at all on the internet?

Amazon not so long ago worked without JS, or Ebay, I can't remember.

Re: I Love Arch, but GNU Guix Is My New Distro

#274

Earlier quoted context omitted.

There is no way to verify silicon. This applies to every single chip. If you are using off the shelf hard cores in silicon, you need to trust the vendor. That's just how it is. It's not practical for end users to take silicon chips into a SEM, delayer them, and verify that the design is what they expect. Verifiability aside, there aren't even any high performance CPUs with fully open RTL/netlists available.

> If you are using off the shelf hard cores in silicon, you need to trust the vendor if i dont have options for alternatives, i think its completely rational to use something without trusting it. i would say that this should be a default attitude

Sandboxing and fencing off untrusted parts is fine. I find the approach of Librem 5 understandable.

However the distinction between blob on chip flash and blob on system storage is nonsensical to me. I would much rather have a sandboxed untrusted part I can update rather than a sandboxed untrusted part that I can not update.

Unfortunately I have not seen anyone actually give a reason why the line should be drawn there instead of closed source blobs are not ok period. Doesn't matter where they live. None of us are arguing in favour of blobs.

Re: I Love Arch, but GNU Guix Is My New Distro

#275

Earlier quoted context omitted.

Nobody is looking at Intel's microcode mask ROM. It's in ROM. You can't even look at it. Microcode is a bad example because the updates are encrypted too, but for the vast majority of the blobs that the FSF hates so much, at least you can look at them and audit them with a disassembler. Meanwhile, the devices with giant firmware ROMs that they openly endorse are not auditable, as you can't see the blob. This policy i…

so after so many posts this is the only one that expresses your point clearly. notice how it does not contain any FUD to the said point, this is definitely a VALID security concern. FSF needs to make these concerns clear. you seem to be very invested in this matter. have you raised these concerns with them? EDIT: having thought about it some more. doesnt isolating blobs to ROMs restrict the problems to ROMs? i mean n…

People have raised these concerns. I have personally raised this concern directly to RMS at one of his conferences.

It gets ignored.

I believe it is for the same reason religions ignore issues.

The FSF totally acts as a religion. The church of his Gnusance St. Ignutiutus. And just like religions it pretends to hold an ethical position while making compromises for practical reasons.

Compare religions claiming:

- Killing is bad, unless it's about opponents in war. - Slavery is bad, unless it's outsiders who are slaves. - Blobs are bad, unless they are stored on chip flash.

The FSF gets criticized precisely for this hypocrisy. And just like religions ignore criticism about their inconsistencies so does the FSF.

Re: I Love Arch, but GNU Guix Is My New Distro

#276
post #270

Earlier quoted context omitted.

> As has been shown plenty of times, “more eyes looking at the code” is a fallacy This is debatable: https://en.wikipedia.org/wiki/Comparison_of_open-source_and_... . Any links to your argument?

Your link says they are comparable, with another study claiming better quality for open source software. While I really don’t think that grouping together vastly different softwares based on this one quality is meaningful (is a proprietary CRUD app made in 5 months with an ad-hoc architecture comparable to an open source database with proper planning and domain-expert programmers working on it?), I also didn’t claim…

https://www.fsf.org/blogs/community/who-actually-reads-the-c...

Re: I Love Arch, but GNU Guix Is My New Distro

#277

Earlier quoted context omitted.

so after so many posts this is the only one that expresses your point clearly. notice how it does not contain any FUD to the said point, this is definitely a VALID security concern. FSF needs to make these concerns clear. you seem to be very invested in this matter. have you raised these concerns with them? EDIT: having thought about it some more. doesnt isolating blobs to ROMs restrict the problems to ROMs? i mean n…

People have raised these concerns. I have personally raised this concern directly to RMS at one of his conferences. It gets ignored. I believe it is for the same reason religions ignore issues. The FSF totally acts as a religion. The church of his Gnusance St. Ignutiutus. And just like religions it pretends to hold an ethical position while making compromises for practical reasons. Compare religions claiming: - Killi…

>The FSF totally acts as a religion. The church of his Gnusance St. Ignutiutus. And just like religions it pretends to hold an ethical position while making compromises for practical reasons.

so is FSF dogmatic or is it practical? surely they cant be both

Re: I Love Arch, but GNU Guix Is My New Distro

#278
post #233

Earlier quoted context omitted.

I fully believe in software freedom (including favoring the GPL), and am trying to push it forward with this argument. I just see using a "6300 with microcode 2019-12-18" as the exact same compromise as using a "6200 with microcode 2011-11-14", regardless that the first blob was loaded at runtime while the second blob was loaded at the factory. Neither one lets me audit or modify my processor. There aren't many perfo…

It sounds like we have very similar beliefs. I think the FSF should acknowledge that microcode updates and such are odious but tolerable moral compromises and that we should continue to work for a future where we have complete freedom to modify, repair, and otherwise use our machines as we see fit. However, for fun, I'm going to do my best to steelman the FSF position: The use of non-free software when no free altern…

I think the FSF position comes to down to 1. It's what they've always done and 2. They don't want to be distributing any nonfree software, even when it wouldn't become part of the Free environment

Whereas having a background in embedded design, I can't ignore that I have many more devices running nonfree software than Free software, despite trying to use Free software wherever I can. In particular, my fully Free desktop relies on non-free { monitor, monitor remote, keyboard, mouse, USB hubs, USB hub PS (power supply), USB switch, UPS, network power switch, circuit breaker, ethernet switch, ethernet switch PS, GPON terminal, GPON PS, nonfree BIOS on router }, in addition to the contentious non-free { video card, network card, CPU }. Any and all of those things could be replaced with a Free equivalent, but at the cost of attention that would be better spent elsewhere. In a world being eaten by software, the best we can do is hope for well-defined interfaces with nonfree systems, for our Free systems to interoperate with.

Perhaps a good way forward would be to split (Nonguix, Debian non-free, etc) into two separate categories depending on whether a package runs in the main security domain (drivers, system software, utilities/applications), or is to be loaded into an auxiliary processor (firmware blobs). Then after this distinction became widely accepted, the Free-first distros would hopefully become more comfortable including the firmware blobs, making a better user experience for their Free environments without impinging upon the freedom within.

(FWIW your steelman isn't it - it would seem to indicate that buying a computer with MS Windows preloaded is good from a software freedom perspective)

Re: I Love Arch, but GNU Guix Is My New Distro

#279
post #218

Earlier quoted context omitted.

If the kernel can't load it without code changes and recompilation, due to the de-blobbing process, it doesn't make much sense to recommend to users that they load it.

You can often also update your microcode by updating your BIOS/firmware.

That's a good point! Adjusting the message to direct people down that route rather than simply removing it seems like a good idea.

Re: I Love Arch, but GNU Guix Is My New Distro

#280

Earlier quoted context omitted.

People have raised these concerns. I have personally raised this concern directly to RMS at one of his conferences. It gets ignored. I believe it is for the same reason religions ignore issues. The FSF totally acts as a religion. The church of his Gnusance St. Ignutiutus. And just like religions it pretends to hold an ethical position while making compromises for practical reasons. Compare religions claiming: - Killi…

>The FSF totally acts as a religion. The church of his Gnusance St. Ignutiutus. And just like religions it pretends to hold an ethical position while making compromises for practical reasons. so is FSF dogmatic or is it practical? surely they cant be both

It's definitely both -- it's just that the dogma is broad, and they appear to very carefully and intelligently choose battles. The dogma is "long term software freedom." This includes occasionally accepting that there are battles not worth fighting (or better yet, fighting strategically.)

A really simple example is GPL violations. Pure dogma would require that they try to fight a whole lot of them, since they occur all the time and they're clearly in the legal right.

But they don't, and that's the MUCH SMARTER way to go.

Why this Guix thing strikes me as smart is that it's about "reinforcing modularity." They can't free up EVERYTHING, but they can make the software work different so that it's harder to pretend that everything is all the same.

Post reply on HN