5 ms·
After using apt-get for everything, going back to manually finding an (untrusted) executable, running it, hitting a bunch of next buttons -- seems insane. It i
by Peaker 11y ago
After using apt-get for everything, going back to manually finding an (untrusted) executable, running it, hitting a bunch of next buttons -- seems insane.
It is quite bad. External dependencies are also nearly impractical this way, so all installers tend to embed their universe of dependencies, making for an even worse experience.
- moron4hire 11y agoUntrusted by whom? It's the same vendor whether it comes from their site or the package repository. And maybe people include way too many dependencies in their projects if it's too much to manage manually. Also, installers are perfectly capable of managing dependencies.
- subway 11y agoIt's the same vendor whether it comes from their site or the package repository. Prove it. The package manager allows you to cryptographically verify the binary was inspected by somebody you trust (the package maintainers). While windows has added code-signing/verification capabilities, many installers are unsigned, and those which are signed don't have a useful trust anchor.
- moron4hire 11y agoProve the repository maintainer doesn't blanket approve things because they are overwhelmed.
- voltagex_ 11y agoThat's what the mailing list / debbugs are for. Each package has a maintainer(s) who are responsible for looking after the package creation and upload. A new upload creates an audit trail that could be checked if needed.
- deleted 11y ago[deleted]
- jimmaswell 11y agoAfter simply using installers in Windows, dealing with conflicting package and library dependencies seems insane. I've been unable to use multiple applications on linux because of this issue whereas that would never happen on Windows where installers just have what they need without getting in each other's business.
- debacle 11y ago> installers just have what they need Have you ever tried writing a Windows installer?
- moron4hire 11y agoYes, several. Have you?
- mwcampbell 11y agoWhat exactly is your point? Applications bundling their dependencies is the norm on all mass-market desktop and mobile platforms. So commercial developers of packaged software are used to it. Such developers even tend to bundle dependencies when targeting Linux, if they want to be distro-agnostic. In this respect, developers of open-source software are spoiled, because they can delegate dependency handling to the distro or, in many cases, the user.
- vacri 11y agoSo, I had to clean some viruses off a Windows 7 machine for a friend recently. I had to grab about six different bits of anti-malware software to do so. Some of that software came from famous vendors' sites where the downloaded software wasn't even protected by https. No real way to externally validate the item I was about to install on a system which is already known to be compromised. Some of the installers tried to install bundled crapware - which is frequent in the Windows world, and you have to watch out for it with every installer. I hadn't done any real work on Windows for so long that I'd forgotten the whole "is this even safe to download?" problem that Windows has with it's applications.
- 11y ago