3 ms·
What I don't like in Debian: - 3rd-party software is not welcome; there is no mechanism for installing it securely because you are supposed to either install s
by codedokode 3y ago
What I don't like in Debian:
- 3rd-party software is not welcome; there is no mechanism for installing it securely because you are supposed to either install software from official repository or compile what you have written yourself. For example, if you want to install Sublime Text, or VS Code, there is no way to do it securely, without giving untrusted software access to your browser history and SSH keys. Of course, you can ignore security and run sudo curl http://script http://script , but it doesn't guarantee that the installer won't break something. It is like we are back in 95 when every second program would replace system DLLs in Windows folder and break other software.
- there are third-party repositories, but they can cause conflicts and you better not use them, but there is no other way to install third-party software.
Third-party software is very important, I install OS to run it, and it surpises me that Linux is so unfriendly to third-party software, including closed-source software and doesn't provide means to install and run it securely and reliably and without making developers adapt it to every existing distribution.
- their bugtracker is email-based and as I don't use email it is completely alien to me. But maybe this is not bad because it stops most of people from posting bugs and saves time to reply to them.
I also tried Fedora, and here is what I don't like:
- they release a new version every 6 or 12 months and it is incompatible with older version, and you have to use a very weird way to upgrade: first, you need to install non-standard plugin (dnf-plugin-system-upgrade), then you need to download packages, then reboot into a temporary OS, then if everything is ok, it will create a new OS, and reboot into it. It looks complicated, easy to break and probably requires a lot of disk space, while Debian can upgrade everything in place.
- if a system component like Gnome is crashing, there will be neither log records nor crash dumps and you will never figure out why it has crashed
Also, APT is buggy when dealing with mixed 32-bit/64-bit packages: I wanted to install a package once and it suggested to delete half of the system to do it; luckily I have noticed that the package list is too long before agreeing. Why would package manager delete packages when I ask to install something, I don't understand. As a bugtracker requires using email, I didn't report it, and it would be difficult to reproduce this anyway.
- Karellen 3y ago> For example, if you want to install Sublime Text, or VS Code, there is no way to do it securely, without giving untrusted software access to your browser history and SSH keys. First, if you don't trust a bit of software, why are you installing it? But more importantly - you don't want your text editor to be able to open and edit your browser history files, or your ssh key files? If my text editor wasn't able to open and edit those files, I'd consider it extremely broken!
- Timber-6539 3y agoIs VS Code a text editor? I wouldn't consider anything that has internet access permissions or a suite of 3rd party user plugins/extensions a text editor but that's just me. Giving VS Code express permission to your home/filesystem (the default if you install it traditionally) is a security risk [0] [1] most people rarely think about. [0] https://blog.aquasec.com/can-you-trust-your-vscode-extensions https://blog.aquasec.com/can-you-trust-your-vscode-extension... [1] https://www.techradar.com/news/hackers-are-using-malicious-microsoft-vscode-extensions-to-steal-passwords https://www.techradar.com/news/hackers-are-using-malicious-m...
- Karellen 3y ago> Is VS Code a text editor? Um, I thought it was? I've not used it, because I'm happy with (neo)vim for my dev needs, but I thought that's what it did? If VS Code isn't used to edit text, what is it for? Edit: (neo)vim and emacs both have 3rd party extension ecosystems, with extensions written in languages that can access the internet, so I'm not sure how that affects your test?
- Timber-6539 3y agoNano is a good example of a text editor.
- codedokode 3y ago> First, if you don't trust a bit of software, why are you installing it? The more people you trust, the larger is the chance that you get deceived. > But more importantly - you don't want your text editor to be able to open and edit your browser history files, or your ssh key files? Only with my permission.
- codedokode 3y agoEven if you trust the developer (I don't), there is a chance that there is a bug or vulnerability in the software. Also you need to install different plugins from random anonymous guys from Github, and it is difficult to trust an anonymous person.
- gsliepen 3y agoAlmost all software that Debian packages is 3rd-party. The issue is usually that software like Sublime Text or VS Code is non-free. That is not in itself an impediment for being packaged; after all there is the "non-free" section of the archive. However, often non-free software is also not free to be distributed by third parties. Thus, Debian would break the law if they did. You don't need to adapt your software that much to have it run on Linux distributions; there are standards that the distributions implement that you can rely on. Often software that claims to only support one particular distribution will run perfectly fine on others. Linux distributions are not unfriendly towards third party software, but they have no obligation at all to spend effort to make that software work, it's the third parties that should do that work. The bug tracker being email based is because when Debian started, that was the normal way to communicate on the Internet (besides IRC). A lot of tools were built on it, and the Debian developers themselves are used to it, so there is little incentive to change this. The Debian developers would say that apt is not buggy; it's just that if there are conflicts, they have to be resolved in some way, which means deleting some of the conflicting packages. It also does ask you to confirm in this case. Although it would indeed be better if it would detect this is a very unsatisfying solution.
- mdwalters 3y ago> if a system component like Gnome is crashing, there will be neither log records or crash dumps and you will never figure out why it crashed On Fedora you can use ABRT (AKA Problem Reporting) to view logs and tracebacks of a component that has crashed, and report the problem via Bugzilla. Also, GNOME isn't a system component, Fedora would still work without it, but it would use a TTY terminal instead.
- codedokode 3y agoAbrt (problem reporting window) shows no information about that type of crash.