I think the last twenty years of quasi-marketing/sales/recruiting DevRel roles have pushed a narrative of frictionless development, while on the flip side security and correctness have mostly taken a back seat (special industries aside).
I think it's a result of the massive market growth, but I so welcome the pendulum swinging back a little bit. Typo squatting packages being a concern at the same time as speculative execution exploits shows mind bending immaturity.
There are good middle grounds, but most package managers don't even acknowledge other concerns as valid.
I don't think security was traded away for convenience. Everything started with convenience, and security has been trying to gain ground ever since.
>happen for people to start taking security seriously
Law with enforced and non-trivial consequences are the only thing that will force people to take security seriously. And even then, most probably still wont.
Security is good, but occasionally I wonder if technical people don't imagine fantastic scenarios of evil masterminds doing something with the data and manage to rule the world.
While in reality, at least the last 5 years there are so many leaders (and people) doing and saying so plainly stupid that I feel we should be more afraid of stupid people than of hackers.
Society works by agreements and laws, not by (absolute) secrecy.
There are of course instances like electrical grid stopping for days, people being killed remotely in hospitals, nuclear plants exploding, that would have a different impact and we might get there, just that it did not happen yet.
It’s similar to how most people are distressed after a break-in, because they considered their home to be a private space, even though the lock manufacturer never claimed 100% security (or the thieves simply bypassed the locks by smashing a window).
Agreements and laws don’t solve that problem, because thieves already aren’t stopped by those.
You can get secure and easy-to-use tools, but they typically have to be really simple things.
Dependency management tools are tools that come about because it's easier and more natural for a programmer to write some code than solve a bigger problem. Easier to write a tool than write your own version of something or clean up a complex set of dependencies.
If Linux had evolved a more sensible system and someone came along and suggested "no actually I think each distro should have its own package format and they should all be responsible for packaging all software in the world, and they should use old versions too for stability" they would rightly be laughed out of the room.
To get to that world, we developers would have to give up making breaking changes.
We can’t have any “your python 2 code doesn’t work on python 3” nonsense.
Should we stop making breaking changes? Maybe. Will we? No.
This only happens because distros insit on shipping python and then everyone insisted on using that python to run their software.
In an alternate world everybody would just ship their own python with their own app and not have that problem. That's how windows basically solves this
Of course I grew up when hard drives were not affordable by normal people - my parents had to save for months to get my a floppy drive.
Having every package as part of a distribution is immensely useful. You can declaratively define your whole system with all software. I can roll out a desktop, development VM or server within 5 minutes and it’s fully configured.
There is currently a gazillion forks, some being forks of forks because they weren't considered culturally pure enough for the culturally purged fork.
Hopefully Determinate Systems or Ekela can get some real maturity and corporate funding into the system and pull the whole thing out of the quagmire.
This can't be real. Are you sure it was something innocuous and not something bigoted?
https://discourse.nixos.org/t/breaking-doge-to-recommend-nix...
Same author quoted the original text on their Reddit thread and was mostly uncriticized there:
https://old.reddit.com/r/NixOS/comments/1joshae/breaking_dog...
I personally found it incredibly distasteful and also fairly representative of the quality of conversation you often get from some of the Nix community. I'm not offensive, you're just thin skinned, can't you take a joke, etc. is extremely common. You'll have to judge for yourself whether it's bigoted or dog whistle or neither.
I'm a former casual community member with modest open source work in that ecosystem (projects and handful of nixpkgs PRs) before I left permanently last spring. I no longer endorse its use for any purpose and I seek to replace every piece of it that I was using.
I still hear about the ways they continue to royally fuck up their governance and make negligible progress on detoxifying the culture. It took them until last fucking week to ban Anduril from making hiring posts on the same official forum.
>I personally found it incredibly distasteful
How? Why? It's clearly satire, written in the style of The Onion.
>and also fairly representative of the quality of conversation you often get from some of the Nix community
Good satire? At least some members aren't brainrotted out to the point of no return.
> I'm not offensive, you're just thin skinned, can't you take a joke, etc.
It's clearly not offensive and if that upset you, you clearly have thin skin and can't take the blandest of jokes. Histrionic.
>I no longer endorse its use for any purpose and I seek to replace every piece of it that I was using.
I will also tell others not to use Nix after reading that. The community is indeed too toxic.
>I still hear about the ways they continue to royally fuck up their governance and make negligible progress on detoxifying the culture.
They won't detoxify until they remove all the weak neurotic leftist activists with weird fetishes for "underrepresented minorities."
>It took them until last fucking week to ban Anduril from making hiring posts on the same official forum.
I'm not sure who that is or why it's an issue, but I assume it's something only leftists cry about.
I agree that the infighting is not nice. But to be honest, when you just use NixOS and submit PRs, you do not really notice them. It's not like people are fighting them in the actual PRs to nixpkgs.
Ironically enough the closest comparison I could make is driving a Tesla. Even if the product is great, you're supporting an organisation that is the opposite.
I think the Nix team will continue to slowly chase away competent people until the rot makes the whole thing wither, at which point everyone switches their upstream over to Determinate Systems' their open core. Although I'm hoping DS will ultimately go the RHEL-Fedora route.
Yeah, because they allow anyone to contribute with little oversight. As Lance Vick wrote[1], "Nixpkgs is the NPM of Linux." And Solène Rapenne wrote[2], "It is quite easy to get nixpkgs commit access, a supply chain attack would be easy to achieve in my opinion: there are so many commits done that it is impossible for a trustable group to review everything, and there are too many contributors to be sure they are all trustable."
[1] https://news.ycombinator.com/item?id=34105784
[2] https://web.archive.org/web/20240429013622/https://dataswamp...
Of course, Debian developers/maintainers are vetted more. But an intentional compromise in nixpkgs would be much more visible than in Debian, NPM, PyPI or crates.io.
I present to you sibling comment posted slightly before yours: https://news.ycombinator.com/item?id=43655093
They do.
I brought up Arch because they get a lot of hate for exactly doing that and consequently pulling people's legs out from under them.
Prime example of this is what the Bottles dev team as done.
It isnt an easy problem to solve.
System perl is actually good. It's too bad the Linux vendors don't bother with system versions of newer languages.
App store software is excruciatingly vetted, though. Apple and Google spend far, far, FAR more on validating the software they ship to customers than Fedora or Canonical, and it's not remotely close.
It only looks like "randos" because the armies of auditors and datacenters of validation software are hidden behind the paywall.
Also Windows and Mac have existed for decades and there's zero vetting there. Yeah malware exists but its easy to avoid and easily worth the benefit of actually being able to get up-to-date software from anywhere.
Isn't that only for applications? All the system software are provided and vetted by the OS developer.
The nice thing about Debian is that you can have 2 full years of routine maintenance while getting reading for the next big updates. The main issue is upstream developer having bug fixes and features update on the same patch.
The vetting on Mac is that any unsigned software will show a scary warning and make your users have to dig into the security options in Settings to get the software to open.
This isn't really proactive, but it means that if you ship malware, Microsoft/Apple can revoke your certificate.
If you're interested in something similar to this distribution model on Linux, I would check out Flatpak. It's similar to how distribution works on Windows/Mac with the added benefit that updates are handled centrally (so you don't need to write auto-update functionality into each program) and that all programs are manually vetted both before they go up on Flathub and when they change any permissions. It also doesn't cost any money to list software, unlike the "no scary warnings" distribution options for both Windows and Mac.
Hahah! ...they don't. They really don't, man. They do have procedures in place that makes them look like they do, though; I'll give you that.