[-] bitfucker@programming.dev 1 points 1 month ago

I feel like I'm missing something still. From my understanding just copying the file doesn't always work (unless it is an installer). So option 1 would still need more work? That's why my assumption goes to running the game directly off of the NAS

[-] bitfucker@programming.dev 1 points 1 month ago

The latency not to mention the speed of NAS would be limited compared to local NVMe. So if you install a game on NAS, it may take a while to load. Of course it also depends on the specific games, but generally it is not a good idea to install heavy programs on a network unless that program is specifically made for network use (think, collabora)

[-] bitfucker@programming.dev 1 points 2 months ago

I know where you're coming from when you say they are different. But I disagree on that because at the end of the day you're still trusting other people would not act maliciously or get their account compromised. The selection process doesn't make it any more special as demonstrated by xz in my example.

Anyone can be an AUR submitter and maintainer. Act in good faith and never become an Arch maintainer. Someone can be an Arch maintainer and be good for a few years then something happened and their account got hacked or bad blood made them act rashly.

That's precisely what I mean when I equate AUR maintainer to the distro maintainer. To the package management system, they are both trusted. Not in the sense of how special they are or how strongly you can trust one but not the other.

[-] bitfucker@programming.dev 1 points 2 months ago

Yes, and that is no different than distro maintainer that maintains the infrastructure and package. Anyone can volunteer. That's how xz is compromised. The point is that aurto trust models mimic those of other package managers. Trusting the authors implicitly trust the code. The only other special things from distro maintainer is their PGP signatures are required to perform release on the main repo. This is better because as I stated earlier, reviewing PKGBUILDS would encourage people to just skip it. Not everyone has the time for that. But when a maintainer changes? Aurto removes the package for you to perform that first trust again on the new maintainer. This is no different than if you update the arch keyring just more manual

[-] bitfucker@programming.dev 1 points 2 months ago

Well, it is just like a distro maintainer account anyway. If the maintainer account is compromised then gg for the whole distro. That's what happens with other supply chain attacks as well and yes, I do think we need a way to fix that without compromising on ease of usability

[-] bitfucker@programming.dev 1 points 2 months ago* (last edited 2 months ago)

Edit: Sorry I realize my rambling didn't answer your question. My suggestion is to not use aura. I do not see anywhere on their repo about their trust model or if they just do it like yay/paru. This is also why I recommend aurto and not aurutils. People would just skip the diff with aurutils.

The thing is, aurto is not the helper. The helper is aurutils. aurto is just the local repo manager that adds timer to auto-update and some QoL features. But to add packages to that local repo, you need to add the maintainer to the trust list. That means the current attack of adopting orphaned / unmaintaned packages is moot. The maintainer change means the package are kicked out and not tracked anymore by aurto. You can still re-add them after you've confirmed that they're safe.

That being said, aurto do have issue. They trust the PKGBUILD of the author/maintainer so if the maintainer got hacked or gone rogue, it will not protect you. Same as with every other package manager in that case.

[-] bitfucker@programming.dev 1 points 2 months ago

Man, it's a shame they block me (probably because of my IP range)

[-] bitfucker@programming.dev 1 points 2 years ago

Alright, let's put it this way. You buy a disc with a license key to access its content. You copied the disc content AND the license key. Now, as you said, you own the disc and the software and license. Next, since you own it, you sell your disc for whatever reason. You own it right? So you can sell it. But, do you think you are still entitled to the data that you have copied beforehand?

[-] bitfucker@programming.dev 1 points 2 years ago

I didn't follow the saga but, have you tried reflashing the firmware and reinstalling klipper? Also, where did you run klipper from? Did you have a spare sbc to test on? Some incorrect software behaviour could also be a result of hardware failure or malfunction that wasn't really visible.

[-] bitfucker@programming.dev 1 points 2 years ago

Why not try flutter then?

[-] bitfucker@programming.dev 1 points 2 years ago

Yeah, and that is true for a lot of service. Sybil attack is indeed quite hard to prevent since malicious users can blend with legitimate ones.

view more: ‹ prev next ›

bitfucker

0 post score
0 comment score
joined 2 years ago