[-] [email protected] 35 points 1 month ago* (last edited 1 month ago)

If such a project were to become compromised (the way XZ-Utils was), it would eventually spread to Ventoy.

What a lot of people don't know is that the XZ attack entirely relied on binary blobs: Partially in the repo as binary test files, and partially in only the github release (binary).

If someone actually built it from source, they weren't vulnerable. So contrary to some, it wasn't a vulnerability that was in plain view that somehow passed volunteer review.

This is why allowing binary data in open-source repos should be heavily frowned upon.

[-] [email protected] 33 points 1 month ago* (last edited 1 month ago)

For instance, Discord shouldn't be a thing since IRC exists, but Discord exists and is very successful.

IRC lacks a massive amount of features that discord users typically want. Screensharing, VCs with group and camera support, built-in history (don't need to use a bouncer like on IRC), built-in online GIF searcher and sender with one click, huge community of bots that use discord's API to do anything from games to moderation.

It isn't even close.

[-] [email protected] 26 points 1 month ago

Until we end tipping culture, tip your servers.

If everyone continues to tip by default, then I believe this will delay or prevent an end to the culture. If servers don't have an issue with tipping (because everyone does so), then there is less reason to support change.

If one person doesn't tip:

You're just an asshole.

If a large majority doesn't tip:

Maybe there is a problem with tipping by default?

[-] [email protected] 28 points 2 months ago* (last edited 2 months ago)

I believe the bandaid needs ripping off.

Just like how community effort into making windows more tolerable never solves the fundamental problem of it being closed-source and out of your control, Firefox being largely dependant on Google, while fighting against privacy invasion and ads creates a conflict of interests.

This is solved by removing the influence

[-] [email protected] 24 points 2 months ago

but Blåhaj can't demand that their rules be enforced in other instances.

They can and they did.

I think most instances have a baseline of what is not acceptable, even on other instances. This is one of those baseline rules.

3
submitted 3 months ago by [email protected] to c/[email protected]

Helix is great, but please why can't indentation just be what is set in the language.toml file?

[[language]]
name = "zig"
indent = { tab-width = 8, unit = "\t" }

Changing indent-heuristic doesn't fix it. Why does helix give me the option to set the indentation style and then proceed to overwrite it, Instantly resetting it to 4 spaces instead of what I told it.

The behavior that is occurring is extremely weird and would be instantaneously solved if helix would just use the value in the file.

I don't want your garbage heuristic, I just want you to leave my file alone and do what I told you.

[-] [email protected] 21 points 3 months ago

Disappearing messages people!

[-] [email protected] 34 points 3 months ago* (last edited 3 months ago)

Security is much more effective and adopted when it is simple. My understanding is that SELinux is not.

This means not only will fewer people use it and more people turn it off if something doesn't work, it means more people are at risk of misconfiguring their system to allow something they didn't intend to.

This is somewhat mitigated from the fact that, from my experience, Linux Security Modules cant ever make you less secure than without it. But it still can provide a false sense of security if you misconfigure it.

Here is a good article showing what I am referring to, and providing a solid security tool: BSD pledge/unveil on Linux.

[-] [email protected] 73 points 3 months ago

If you're going to censor something, use an opaque black shape. These half-ass censorship attempts are ridiculous.

[-] [email protected] 30 points 3 months ago* (last edited 3 months ago)

I'll take a program that isn't getting updates anymore or simply wasnt working in my modified environment using slightly more ram and storage over it not working at all.

I have firsthand experience with videogames made for one flavor of Linux not working on my machine due to dependency hell.

[-] [email protected] 45 points 3 months ago

This is a good reason for static linking. All the dependencies are built into the binary, meaning it is more portable and future proof.

We don't need flatpak for this!

[-] [email protected] 30 points 4 months ago

Linus already has a backup. Its Greg Kroah-Hartman.

[-] [email protected] 34 points 4 months ago

Blanket, emotional statements are harmful.

view more: next ›

unhrpetby

0 post score
0 comment score
joined 4 months ago