Hard drive cost $/B continue to fall: https://www.backblaze.com/blog/hard-drive-cost-per-gigabyte/
Self-hosting is looking more and more attractive.
There are still lots of reasons to consider alternative hosting providers (the biggest one: egress) but that blog post--frequently reposted and annoyingly misleading--is not a good summary of the situation here.
Bad example. "Latency", if it can even be called that, is 12-48 hours.
It's not cloud storage, it's archiving.
I wish they were less concerned with where they artifacts are stored and more about how nixpkg can prove they are authentic and who authored them.
Nix has so many innovations over other other distributions but the massive step backwards in supply chain integrity still makes it too dangerous to use for any system you would not trust strangers with ssh access to.
Supply chain security is of course a massively multifaceted technical and social problem, but I’m curious what other distributions you think are doing it better in practice?
Also no signed commits or signed authorship means someone with Github access can just fake history and inject whatever they want after code reviews are completed, which will then be blindly and automatically signed.
Some of the people with write access to the nixpgs repo even have SMS recovery enabled on their github recovery email accounts. One sim swap to compromise all nix users. I will not call them out, but go try to do a email password reset on recent committers for yourself. A malicious github employee could also of course do whatever they want to an unsigned repo. Or a well placed BGP attack. Lots of options. It is hard to prevent such things, but author commit signing would mitigate the risk and can be enforced.
I made my case for this to the nix team but in the end it was concluded people would stop maintaining packages if they had to do the bare minimum like commit signing or hardware 2FA. https://github.com/NixOS/rfcs/pull/34
All this is fine, but it means effectively a decision was made for NixOS to be a hobby distro not suitable for any targeted applications or individuals. It really sucks, because I love everything else about nix design.
Instead I am forced to bootstrap high security applications using arch and debian toolchains which are worse than nix in every way but supply chain integrity given that all authors directly sign package sources with their personal well verified keys. They have a ton of other security and even their own supply chain problems but they at least can survive phishing, a malicious mirror, or a sim swap. It is a low bar nix sadly does not meet.
But the way I understand it, the current trust model is no different than any other package manager, so this hardly seems like a fair criticism.
Compare to arch, fedora, debian, and basically every other linux distro that has existed more than a decade. Every maintainer signs their own contributions with well known keys so they cannot be impersonated and so later stages of the supply chain cannot tamper with them.
Newer distros like Nix and Alpine decided do get rid of all that security overhead in order to attract a huge pile of randos as maintainers. I mean, it worked, but at a very high price.
How can anyone know the Hydra signing key was not tampered with?
These are problems other linux distros have solved for decades by just requiring maintainers press a blinking yubikey or similar to sign their contributions.