Maragato

joined 1 year ago
[–] Maragato@lemmy.world 1 points 2 weeks ago (1 children)

That is, you admit that most aur users delegate that function to other eyes instead of auditing the external code they are installing. A user repository outside of the official distribution repository is not a secure means of installing packages on the system, which may have root access to the system and the source code may change with each package update. Do you think that every time there is an update to a package that is not widely used, others will audit the source code for you? For that reason I stopped using Aur and by extension Arch, as their software catalog outside of aur is small.

[–] Maragato@lemmy.world 5 points 2 weeks ago* (last edited 2 weeks ago) (9 children)

Any major Linux distribution has a system for building packages, it's not something special to Arch. In fact, Arch's great advantage of the aur repository actually becomes a disadvantage by introducing instability and insecurity into your system when you add programs from that repository. It's amazing that people criticize Windows security with .exe's and then install packages from external repositories with the security of "trust in the repository". How can you trust code with root access to the system just because it's in the aur repository? That's the main question I would ask Arch users.

[–] Maragato@lemmy.world 52 points 2 weeks ago (6 children)

Most of the time it is achieved with the phrase: "I use Arch, btw". 😉

[–] Maragato@lemmy.world 38 points 1 month ago* (last edited 1 month ago) (4 children)

SUSE has its line of business in servers and cloud computing. Opensuse has desktop users as its main asset. Not wanting the company's name to appear on the distribution is because the typical users of the two are increasingly different, as well as suspecting that Leap will not continue as SLE's 1:1 solution. Suse's decision not to have its name on the distribution means that it will be increasingly distanced from the community distribution, which is primarily run by Suse employees, so it is the company's decisions that will shape the future of the distribution.
A company's decisions are based on the benefits of its line of business, not on the benefits of the community outside its customers. This is a statement of intent that in my opinion breaks the relationship of trust between company-community. It is time to look for another distribution, the chameleon has focused on its profits rather than on the benefits for the community.

 

I have always been afraid to install Arch because they tell you it is difficult to install and unstable. I want a simple system following the KISS philosophy and install only what I need, which is little. I don't need anything from the aur repository, for now. Just a year ago I installed Arch and there it is, no problems and doing every day pacman -Syu. It has been a real discovery for me, it's the only distribution I've had this last year that hasn't crashed. I didn't expect it, but Arch has made me change my opinion and pay less attention to the opinions of "youtubers" and more to my own experience. In your experience of use, has Arch been stable in its operation?

[–] Maragato@lemmy.world 16 points 2 months ago* (last edited 2 months ago)

You can install Firefox from Mozilla's own repository. It is a luxury to have in Debian a Mozilla repository to install Firefox.