Conversation
Notices
-
Embed this notice
...
-
Embed this notice
@menherahair i don't know how to fix this shit
-
Embed this notice
@lina he pythoned
-
Embed this notice
@menherahair im too retarded for that
-
Embed this notice
@lina unpython and python it again
-
Embed this notice
@menherahair happens :ryukotired:
-
Embed this notice
@lina same :ryukoPROBLEM:
-
Embed this notice
@eisai i think it's just that python is irreparably fucked on rosa and nobody really cares enough to fix it
-
Embed this notice
@lina Try poking its package manager (pip or something). Perhaps it’s managed with your OS, perhaps you should do it by hand.
-
Embed this notice
@eisai don't wanna risk a slavaukraine from a rogue hohol sympathizer maintaining a distro
-
Embed this notice
@lina > Rosa
> problems
But of course!
-
Embed this notice
@eisai no you don't get why im using rosa, it's not because it's a "secure" distro or some shit
it's just far less likely for a bleeding heart urine fan to be among the maintainers for rosa than it is for a popular distro like arch or some shit
the nodejs incident taught me to not trust opensource shit, especially if it's maintained by someone who's too politically active for a shitcoder
-
Embed this notice
@lina Ugh. I went to the folder with LOR threads, wanting to prove a point, and almost died of puking. The tl;dr of what I meant to say would be that the so-called security in those “secure” distros is relative. I doubt that anyone actually crawled the OpenSSL code with a loupe trying to make sense of it. I had an acquaintance there and he said that he simply runs long automated tests over and over again over new releases. So I presume that they presume the software is a black box, even though it’s open source. You’d have better chances avoiding a backdoor by using half-broken niche replacements for popular libraries and software. Some obscure browser like links and uclibc for libc. Keep your ports closed, too, and run windows software detached from network. Firejail any messaging program. That’s not all, but the bare minimum in addition to just running Linux.
-
Embed this notice
@eisai problem's really is that i literally can't know which one of the chumps who really wants to own the evil vatnik nazi is gonna blow up next, the distro maintainers first and foremost get to try out the package-
ah goddammit, i forgot that rosa's maintainers probably don't even fucking use it daily to actually check half the shit that they upload to the repos, well still, i'll feel like a moron if i hop distros now, i'll wait a little more, be it an actual reason to hop distros or the war ends
-
Embed this notice
@lina You see, Rosa still uses open-source software. Most of which is the same for any distro. What distro maintainers do is simply verify the checksums of the original package, re-wrap it for their package system and off you go, my package. NodeJS issues are NodeJS issues, distro maintainers are not warrants from the evil intent that the creators of the software (or the creators of particular modules) may have. Distro maintainers keep the channel of software delivery, and their primary concern is that it would install and run in the current ecosystem of package versions. Their second concern is to verify, that they themselves get true software, verified by the checksums, and that the end users also receive verified packages (not altered by some third person while the package is downloaded). If the software devs pack in some malicious code, it just gets delivered by those properly maintained channels. It you don’t trust or dislike some open-source, that’s right, wary you should be. But instead of relying on distro maintainers, you should be avoiding or jailing particular software. Ah, whatever… *splisht*
-
Embed this notice
@eisai i know, i know, sunken cost PHALLACY or some shit, i'll figure out how to run syncplay in commandline, the gui shit is optional
-
Embed this notice
@lina
-
Embed this notice
@lina No idea what do you mean, but gambare.
-
Embed this notice
@lina @eisai Debian GNU/Linux doesn't have this issue
(because the packages are older than the war)
-
Embed this notice
@menherahair @lina They must be over ten years old!!