Paradox of Tolerance
"it seems contradictory to extend freedom of speech to extremists who... if successful, ruthlessly suppress the speech of those with whom they disagree"
Paradox of Tolerance
"it seems contradictory to extend freedom of speech to extremists who... if successful, ruthlessly suppress the speech of those with whom they disagree"
Put differently, I can't think of any reason that the #arch package repository is more secure than `https://sh.rustup.rs`.
In either case, a project that I trust manages the security. And if either site were compromised, I'd be in trouble.
Of course, there's something to be said for limiting the number of organizations you trust to the bare minimum
> why do you say it's it ok for rust to [recommend installing via `curl | sh`]?
Well, as I said, because the project is large/established/reputable enough.
The main reason `curl | sh` is bad is that it gives an external actor—or anyone who can compromise that external actor—the ability to execute arbitrary code on your computer.
That means that you need to trust both the good faith and the security practices of the external actor. I'm paranoid, so I rarely do, but do sometimes
that people will argue in favor of curl | bash shows how absolutely fucked our entire software infra is
> that people will argue in favor of curl | bash shows how absolutely fucked our entire software infra is
I *generally* agree, but I'm willing to make a partial exception for extremely large/established/reputable projects (assuming that the download is over https).
For example, the recommended installation method for #rust starts with a `curl | sh` command, and I don't really have a problem with that (though I'm glad they give other options) https://www.rust-lang.org/tools/install
@rain It's not really any worse than git clone xxx;./configure; make; sudo make install
Software is bad and sharing is dangerous.
Has science gone too far?
> I love desktop Linux, but for some reason I find server Linux a chore that I will only do if I'm getting paid.
What do you prefer to use on the server when you're not getting paid?
Big shoutout for #hledger, plain text accounting which can save large fees over conventional accounting software. AND at same time create sustainable access to data, rapid corrections. The alias function for account coding is awesome. Also the include function to unify or consolidate different data files is just sweet. https://plaintextaccounting.org/ and https://hledger.org
trying to download an ebook from the library but there's a two month wait because only so many people can borrow it at a time 🤔
@cwebber I look forward to seeing your ideas get developed and disseminated - thanks for all the thought and effort you put into getting things right.
anyways, #Guix is nice, but having to deal with environment variables is still kind of a pain in the ass
which is why I still maintain that the #Plan9 file system model would be a better base to build upon
Alan Turing - the face of the new £50 note.
It’s too little and too late, of course, to make up for the horrendous way that Turing was treated by the establishment. But it’s a good thing.
https://www.grahamcluley.com/alan-turing-the-face-of-the-new-50-note/
I'll be honest, #rust really helped me in getting locking right in C... in the past 10 months there was not a single locking issue in my code. #iamtheborrochecker
* happiness noises *
> How many of you track your sleep? I do, and it's depressing.
Agreed on both
Damn you, Fedora, you scared me with that screen!
(I actually like this thing, but the flashbacks hit strong)
Playing around with FISH. Who's using it and whats your favourite feature?
Adobe Creative Cloud holds creative works hostage: if you stop paying the monthly fee or if Adobe's servers go down, you can't edit your work. Once you buy into the Adobe ecosystem, you're stuck there and forced to pay rent.
There are many free open alternatives which give you full control over your work without locking you down:
https://switching.social/ethical-alternatives-to-adobe-creative-cloud/
Just before non-binary day ends, I wanna say I'm a proud AF non-binary witch.
This year I came out at work as non-binary, and it's all over my professional life.
I'm grateful for the possibility to do that, and I'm hopeful that it'll encourage other people in my circles to do the same.
> Read carefully: 230 - 220 x 0.5 = ___ You probably won’t believe it but the answer is 5!
Related: an entire blog post walking through/analyzing/admiring that problem and tracing its origin: https://www.shamusyoung.com/twentysidedtale/?p=40810
Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.
All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.