4 ms·
This is why I won't use random distros, even if they have better features. It's just one more point of failure, one more point of unnecessary trust. I would rat
by sgc 9mo ago
This is why I won't use random distros, even if they have better features. It's just one more point of failure, one more point of unnecessary trust. I would rather fight to deal with specific problems with specific apps on one of the handful of core distros with long histories.
- Noaidi 9mo agoAgreed, I just installed Fedora 43. I don’t even trust CachyOS at this point.
- cromka 8mo agoI feel like Cachy is even more fragile than Archlinux.
- bsimpson 9mo agoI feel this way about open source generally. Lots of cool stuff that I happily use, but the bar to installing something that gets to see my password (OS, terminal, input handler, etc) is very high. Not a popular take, but I'd rather run something from Valve or Google for the same reason. I trust there to be more vetting if a corporation is putting its reputation on the product than a toy I found on GitHub. It's a bit of a myth that open source leads to more eyes on the software. Most people just install it and trust that somebody else did the audit. Something with a vibrant community of maintainers? Maybe. Something that's too big to personally audit but too small for that community? I'll pass.
- yjftsjthsd-h 9mo agoThat's not an open source problem, though; that's a supply chain problem. Some random little proprietary freeware isn't better.
- AuthAuth 9mo agoexactly. I remember there was a case where louis rossman covered a repair tool that was hacking its customers if they did something the developer didnt like. At least with open source you have a chance to prevent this. With proprietary its pure trust.
- cromka 8mo agoAnd then there was Gaggiaino that was intentionally bricking displays if you tried to use your own. A project with open source roots. It can happen anywhere, really
- bsimpson 9mo agoSemantics, but yes. The problem isn't the open source (in fact, that's better). The problem is downloading random shit from the internet, and the biased assumption that open-source == trustworthy.
- array_key_first 8mo agoOpen source does not equal trustworthy, but open source repositories usually are trustworthy, because they're trusted repositories. Debian repos are not NPM. Yes, the package are actually vetted to some degree.
- oliwarner 9mo agoI'll take can be inspected over the alternative. I agree, there are companies I'd trust but most software isn't made by Valve and Google. There are plenty of developers also not auditing their dependencies.