Andrew Miloradovsky is a user on functional.cafe. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

I'm seriously thinking about switching from #gentoo to #nixos. Please, talk me down! Somebody!

@newt

Nix Developers don't care about security

"[...] security is not a priority here. Fell free to try to improve security in Nix world, but you are better off with Guix. They even don’t trust compilers w/o bootstrapping from the source option :)"
-Nix Dev
Search for Nix on this page:

srs.gnu.moe/wallofishame/index

#nix #security

@amnesia the only thing about nix there is that stupid curl|sh line, which isn't really worth mentioning

@newt
The key take away is what the developer said about how they don't prioritize security in the distro, which is a big deal imo

@amnesia isn't that sarcasm regarding that line? I'd honestly assume so.

Andrew Miloradovsky @amiloradovsky

@amnesia
The overall attitude of the developers, AFAICT, is that it is simply not security-*focused*. So *if* that's the primary concern for you, better use e.g. .
@newt

@amiloradovsky

@newt

QubesOS is focused on hardline security via isolation. There is a difference between that kind of security, and general good security practices any Linux distribution should follow

@amnesia
Such as chroot'ing the services/daemons accepting an external connections (sandboxing)?
AFAIK, does provide some of that functionality, but I haven't checked.
And there is plenty of "hardening" features enabled by default (which you sometimes have to disable to make a package build).
Honestly, infosec is not my area of interest: I value reliability much more than security, and consider the unintentional issues much more of a problem than the intentional.
@newt